Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

lost network connection activity


  • Please log in to reply

#1
cap10h

cap10h

    Member

  • Member
  • PipPip
  • 14 posts
Hi, I have 2 pc's working on windows xp pro 32bit. no anti virus or firewalls are there. just I use it for browsing. connected to my wired router for Internet. I Had problem last month trying to open any .exe files or .zip and an error message will jump tell me the file is corrupted. today I have new issue which is the connection halt activity with any thing. even trying to ping my router but no respond.
I also try to install the Microsoft security essentials but no way. I scanned this infected pc with other pc having windows xp pro 64bit by the Microsoft security essential and found nothing. just before this connection problem appear.
THANKS for help. Hussain from Kuwait
the report:


OTL logfile created on: 06-5-12 6:50:59 PM - Run 1
OTL by OldTimer - Version 3.2.42.2 Folder = A:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-M-yy

3.00 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 77.58% Memory free
4.84 Gb Paging File | 4.33 Gb Available in Paging File | 89.47% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.29 Gb Total Space | 7.13 Gb Free Space | 38.98% Space Free | Partition Type: FAT32
Drive D: | 96.71 Gb Total Space | 71.25 Gb Free Space | 73.67% Space Free | Partition Type: FAT32
Drive L: | 465.75 Gb Total Space | 463.25 Gb Free Space | 99.46% Space Free | Partition Type: NTFS
Drive M: | 68.36 Gb Total Space | 35.10 Gb Free Space | 51.34% Space Free | Partition Type: NTFS

Computer Name: TYANS2469 | User Name: root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-05-06 18:49:02 | 000,595,456 | ---- | M] (OldTimer Tools) -- A:\OTL.exe
PRC - [2012-03-26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2010-06-21 13:52:32 | 001,414,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\mmc.exe
PRC - [2010-06-21 13:52:26 | 000,388,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) -- C:\WINDOWS\system32\LxrSII1s.exe
PRC - [2009-12-17 20:10:00 | 000,024,576 | ---- | M] () -- C:\Documents and Settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
PRC - [2009-10-24 03:47:58 | 000,409,096 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\WinAVAlarm.exe
PRC - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\3dm2.exe
PRC - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
PRC - [2009-10-16 18:37:22 | 001,325,936 | ---- | M] (Seagate) -- C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
PRC - [2009-03-25 15:32:18 | 000,102,400 | ---- | M] (LSI) -- C:\Program Files\MegaRAID Storage Manager\MegaPopup\popup.exe
PRC - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
PRC - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008-04-13 17:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe
PRC - [2002-10-15 18:00:20 | 001,818,624 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS\mixer.exe
PRC - [2000-04-05 16:03:10 | 000,388,096 | ---- | M] (Meikel.com) -- C:\Program Files\FreeMem Standard\freemem.exe


========== Modules (No Company Name) ==========

MOD - [2009-12-17 20:10:00 | 000,024,576 | ---- | M] () -- C:\Documents and Settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
MOD - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
MOD - [2008-05-12 19:52:06 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\AlertStrings.dll
MOD - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\UPS\upsman\upsman.exe -- (UPSMan)
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\system32\svrwsc.exe -- (SvrWsc)
SRV - [2012-04-17 20:10:22 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) [Auto | Running] -- C:\WINDOWS\system32\LxrSII1s.exe -- (LxrSII1s)
SRV - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] () [Auto | Running] -- C:\Program Files\AMCC\3DM2/3dm2.exe -- (3DM2)
SRV - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) [Auto | Running] -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (SgtSch2Svc)
SRV - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe -- (MegaMonitorSrv)
SRV - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe -- (MSMFramework)
SRV - [2007-01-31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Stopped] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2003-03-03 13:33:40 | 000,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- c:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\Mach3.sys -- (Mach3)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\root\LOCALS~1\Temp\AMDPCI.sys -- (AMDPCI)
DRV - [2011-04-19 17:06:32 | 000,167,584 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\snapman.sys -- (snapman)
DRV - [2011-04-01 21:30:32 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\timntr.sys -- (timounter)
DRV - [2011-04-01 21:30:32 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2011-04-01 21:30:14 | 000,368,480 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\tdrpman.sys -- (tdrpman)
DRV - [2010-06-02 16:05:02 | 000,109,184 | R--- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\symmpi.sys -- (Symmpi)
DRV - [2009-12-30 10:36:56 | 000,063,448 | ---- | M] (Lexar Media, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LxrSII1d.sys -- (LxrSII1d)
DRV - [2009-06-01 13:36:34 | 000,082,432 | ---- | M] (AMCC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\3wareDrv.sys -- (3wareDrv)
DRV - [2009-05-06 08:59:12 | 004,069,376 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009-02-20 19:09:16 | 000,044,032 | R--- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GigasetGenericUSB.sys -- (GigasetGenericUSB)
DRV - [2008-04-13 11:56:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008-04-13 11:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008-01-02 11:07:06 | 001,404,544 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmudax3.sys -- (cmuda3)
DRV - [2007-07-20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006-11-22 10:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2004-06-29 14:25:26 | 000,007,680 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\dontgo.sys -- (dontgo)
DRV - [2004-06-24 18:37:52 | 000,826,752 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmudau.sys -- (cmudau)
DRV - [2002-11-18 15:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002-09-16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001-08-17 12:49:00 | 000,075,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpae.sys -- (atirage3)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.ebay.com/...www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....erify2?&.src=ym
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{2A696BCE-44CF-45a4-B905-59CDFA08531A}: "URL" = http://del.icio.us/s...Terms}&type=all
IE - HKCU\..\SearchScopes\{7B3A7E4E-375E-41FE-B8EC-8D9CCE30AE37}: "URL" = http://search.avg.co...}&ychte=aa&nt=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 184.72.147.41:3128
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = 192.168.222.111


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: D:\canon prog\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files\DAP\DAPFireFox [2011-02-17 00:52:34 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2004-08-04 12:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {78875F5C-A685-4405-8DC5-D48DC65452B0} - No CLSID value found.
O2 - BHO: (Download Accelerator Plus Integration) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\DAP\dapieloader.dll (SpeedBit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [C-Media Speaker Configuration] F:\Cmi8738-6ch\Setup.exe /SPEAKER File not found
O4 - HKLM..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Popup] C:\Program Files\MegaRAID Storage Manager\MegaPopup\Popup.exe (LSI)
O4 - HKLM..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [WinAVAlarm] C:\Program Files\AMCC\3DM2\WinAVAlarm.exe (LSI)
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [FreeMem Pro] C:\Program Files\FreeMem Standard\freemem.exe (Meikel.com)
O4 - HKCU..\Run: [LxrAutorun] C:\Documents and Settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKCU\..Trusted Ranges: Range2 ([http] in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range3 ([http] in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 196.1.69.98 196.1.69.99
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AAC6870A-D985-48FE-9B39-E7D3F8DC8A21}: DhcpNameServer = 196.1.69.98 196.1.69.99
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-06-15 07:41:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell - "" = AutoRun
O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell\AutoRun\command - "" = E:\Windows\CHECK\DriveNavigator.exe
O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell\AutoRun\command - "" = F:\TYANCD.exe
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\AutoRun\command - "" = selomoje\\sranje.exe
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\explore\command - "" = selomoje\\\sranje.exe
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\open\command - "" = selomoje\\\sranje.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012-05-06 17:17:06 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\root\Recent
[2012-05-04 21:05:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3_files
[2012-04-24 23:50:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-04-23 00:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012-04-23 00:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012-04-23 00:30:06 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012-04-21 19:23:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Application Data\ZoomBrowser EX
[2012-04-21 15:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2012-04-21 15:06:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2012-04-18 23:46:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Local Settings\Application Data\CANON_INC
[2012-04-13 00:18:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2012-04-11 01:13:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-05-06 18:10:16 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-05-06 17:26:56 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-05-06 17:19:24 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job
[2012-05-06 17:17:46 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-05-06 17:16:52 | 000,178,544 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2012-05-06 17:16:52 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-05-06 07:52:44 | 000,001,919 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012-05-04 21:14:26 | 000,034,919 | ---- | M] () -- C:\Documents and Settings\root\Desktop\print1_cwlke.pdf
[2012-05-04 21:11:26 | 000,026,065 | ---- | M] () -- C:\Documents and Settings\root\Desktop\Snoopy001_18_zacld.pdf
[2012-05-04 21:06:10 | 000,054,725 | ---- | M] () -- C:\Documents and Settings\root\Desktop\powerpuff_girls1_yfjcs.pdf
[2012-05-04 21:05:36 | 000,002,521 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3.htm
[2012-05-02 00:03:44 | 001,556,821 | ---- | M] () -- C:\Documents and Settings\root\My Documents\ecb350.pdf
[2012-05-01 22:26:52 | 002,012,180 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Clik%202011%20Gear%20Set%20Print.pdf
[2012-04-28 03:36:50 | 002,957,829 | ---- | M] () -- C:\Documents and Settings\root\My Documents\EOS-1Ds-MkII-Whitepaper.pdf
[2012-04-21 15:06:36 | 000,000,594 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:14 | 000,000,461 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-21 07:22:26 | 004,515,558 | ---- | M] () -- C:\Documents and Settings\root\My Documents\canon EOS_1Ds_MarkII user guide.pdf
[2012-04-21 07:15:00 | 009,150,824 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Digital Cameras, Canon EOS-1Ds Mark II Digital Camera Test Image.mht
[2012-04-20 16:42:06 | 000,009,830 | ---- | M] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:02 | 000,393,808 | ---- | M] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:12 | 000,000,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-17 07:15:10 | 000,337,174 | ---- | M] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-15 23:17:24 | 000,019,454 | ---- | M] () -- C:\Documents and Settings\root\My Documents\cc_20120415_231710.reg
[2012-04-13 00:31:20 | 001,742,408 | ---- | M] () -- C:\WINDOWS\System32\MRT.exe
[2012-04-12 22:58:38 | 000,000,000 | ---- | M] () -- C:\WINDOWS\vpd.properties
[2012-04-06 22:48:44 | 000,000,230 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012-04-06 22:48:44 | 000,000,071 | ---- | M] () -- C:\Documents and Settings\root\default.pls
[2012-04-06 22:40:40 | 000,103,936 | ---- | M] () -- C:\Documents and Settings\root\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-05-04 21:14:27 | 000,034,919 | ---- | C] () -- C:\Documents and Settings\root\Desktop\print1_cwlke.pdf
[2012-05-04 21:11:28 | 000,026,065 | ---- | C] () -- C:\Documents and Settings\root\Desktop\Snoopy001_18_zacld.pdf
[2012-05-04 21:06:15 | 000,054,725 | ---- | C] () -- C:\Documents and Settings\root\Desktop\powerpuff_girls1_yfjcs.pdf
[2012-05-04 21:05:33 | 000,002,521 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3.htm
[2012-05-02 00:03:43 | 001,556,821 | ---- | C] () -- C:\Documents and Settings\root\My Documents\ecb350.pdf
[2012-05-01 22:26:51 | 002,012,180 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Clik%202011%20Gear%20Set%20Print.pdf
[2012-04-28 03:36:48 | 002,957,829 | ---- | C] () -- C:\Documents and Settings\root\My Documents\EOS-1Ds-MkII-Whitepaper.pdf
[2012-04-25 00:00:56 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-04-24 23:51:03 | 000,001,919 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012-04-24 23:50:57 | 000,001,651 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-04-21 15:06:34 | 000,000,594 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:12 | 000,000,461 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-21 07:22:25 | 004,515,558 | ---- | C] () -- C:\Documents and Settings\root\My Documents\canon EOS_1Ds_MarkII user guide.pdf
[2012-04-21 07:14:58 | 009,150,824 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Digital Cameras, Canon EOS-1Ds Mark II Digital Camera Test Image.mht
[2012-04-20 16:43:08 | 000,009,830 | ---- | C] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:00 | 000,393,808 | ---- | C] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:11 | 000,000,443 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-17 07:15:04 | 000,337,174 | ---- | C] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-15 23:17:13 | 000,019,454 | ---- | C] () -- C:\Documents and Settings\root\My Documents\cc_20120415_231710.reg
[2012-04-05 00:33:28 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\GkSui16.EXE
[2012-02-16 06:51:36 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011-07-12 09:27:54 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011-06-27 19:30:52 | 000,002,828 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2011-06-26 14:35:48 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\5B3206E10A.sys
[2010-11-11 11:45:58 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\ScsiOat.dll
[2010-10-08 20:16:46 | 000,000,093 | ---- | C] () -- C:\WINDOWS\WFT-E5Utility.INI
[2010-10-03 10:18:19 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010-09-22 05:24:26 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ICOMP.EXE
[2010-09-11 09:41:26 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2010-08-22 23:02:09 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-08-19 16:47:18 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\root\Application Data\$_hpcst$.hpc
[2010-08-18 23:39:52 | 000,000,171 | ---- | C] () -- C:\Documents and Settings\root\Application Data\default.rss
[2010-08-18 23:39:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\root\Application Data\downloads.m3u
[2010-08-17 20:52:06 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\CMRMDRV3.dll
[2010-08-15 07:04:35 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2010-08-15 07:03:21 | 000,479,232 | ---- | C] () -- C:\WINDOWS\System32\Cmeaupci.exe
[2010-08-15 07:03:21 | 000,000,379 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfl
[2010-08-15 07:02:57 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\CmiInstallResAll.dll
[2010-08-15 07:02:57 | 000,003,091 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfg
[2010-08-15 07:02:57 | 000,000,215 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.imi
[2010-08-15 07:02:56 | 000,000,779 | ---- | C] () -- C:\WINDOWS\cmudax3.ini
[2010-08-10 18:37:14 | 000,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2010-07-11 18:20:38 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CmiUSB2Uninstall.exe
[2010-06-30 21:03:01 | 000,000,230 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010-06-27 01:35:33 | 000,002,162 | ---- | C] () -- C:\WINDOWS\Cmudau.ini
[2010-06-27 01:05:53 | 000,000,057 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2010-06-24 23:16:10 | 000,232,840 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.exe
[2010-06-24 23:16:10 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.dll
[2010-06-24 20:51:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010-06-24 15:49:37 | 000,001,150 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2010-06-23 23:58:29 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2010-06-23 22:53:12 | 000,000,112 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2010-06-23 22:53:12 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2010-06-23 22:52:05 | 000,000,246 | ---- | C] () -- C:\WINDOWS\System32\dl.exe
[2010-06-23 07:48:52 | 000,103,936 | ---- | C] () -- C:\Documents and Settings\root\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-06-22 23:06:43 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-06-22 23:06:43 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-06-16 00:27:49 | 001,742,408 | ---- | C] () -- C:\WINDOWS\System32\MRT.exe
[2010-06-15 07:46:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-06-15 07:38:00 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-06-15 07:30:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-06-15 07:29:30 | 000,101,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2010-07-01 23:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010-07-18 19:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gigaset QuickSync
[2010-07-18 20:04:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cached Installations
[2010-08-10 13:02:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2010-09-14 21:12:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grass Valley
[2010-09-14 21:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canopus
[2010-10-10 08:40:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010-10-16 12:07:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AMCC
[2011-02-08 17:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011-02-17 00:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2011-03-15 08:19:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011-03-17 22:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolarWinds
[2011-04-01 21:30:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2011-10-05 22:49:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ClubSanDisk
[2011-10-23 00:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PassMark
[2012-04-21 15:33:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2010-11-23 06:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\HD Tune Pro
[2011-01-06 21:17:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\Eye-Fi
[2011-01-06 21:28:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\fi.eye.center.E430518E652B889A80EC0E8A6E532C09FF36DF62.1
[2011-07-06 20:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\AVG9
[2012-05-06 17:19:24 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
Hello and welcome to Geekstogo!

We apologize for the delay in responding to your request for help.
If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

If you haven't done so yet, please go to Malware and Spyware Cleaning Guide and follow the steps instructed there. If you have already done this, we still need a new log to see what has changed since you originally posted your problem.

We need to create an OTL Report
Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the box that says Scan All Users.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic.

In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. I suggest you do this and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.
  • 0

#3
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thank you Gammo for respond and my apology for my slow respond.
just one thing now. I read in the bottom of your reply says " In the upper right hand corner of the topic you will see a button called Options "
I don't see the options button ?
any way, now I can connect to Internet with the infected pc, in fact i'm writing the topic from the same pc. I just restart the pc in safe mode and try to Clare all temp files and re start the pc. I also run the OTL Run Fix and add the same report note file from OTL and Now it start to connect to Internet and i can browse. just with limited functions, like on ebay site, I CAN'T open pictures and add items to my watch list. In my yahoo I can perform like normal so far.
on the pc, there is also one thins i discover now, if i open any photo from my camera memory or even from saved photos from NAS . it show the photo corrupted or you could say broken picture. put the photo it self is nothing wrong with it. you can see it on other pc or laptop in perfect way.
my main issue is if I need to install any program or download .exe .zip it will show corrupted after download completed.
also I can't update this security file from windows update site [Windows-KB890830-V4.7.exe] it show file corrupt.
I apologize for my bad English.


Thanks for your help. Hussain.



OTL logfile created on: 10-5-12 11:10:30 PM - Run 1
OTL by OldTimer - Version 3.2.42.2 Folder = C:\Documents and Settings\root\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-M-yy

3.00 Gb Total Physical Memory | 2.02 Gb Available Physical Memory | 67.51% Memory free
4.84 Gb Paging File | 4.01 Gb Available in Paging File | 82.72% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.29 Gb Total Space | 6.69 Gb Free Space | 36.57% Space Free | Partition Type: FAT32
Drive D: | 96.71 Gb Total Space | 71.25 Gb Free Space | 73.67% Space Free | Partition Type: FAT32
Drive L: | 465.75 Gb Total Space | 463.25 Gb Free Space | 99.46% Space Free | Partition Type: NTFS
Drive M: | 68.36 Gb Total Space | 35.10 Gb Free Space | 51.34% Space Free | Partition Type: NTFS

Computer Name: TYANS2469 | User Name: root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

========== Processes (SafeList) ==========

PRC - [2012-05-06 18:49:02 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
PRC - [2012-03-26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2010-06-21 13:52:26 | 000,388,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) -- C:\WINDOWS\system32\LxrSII1s.exe
PRC - [2009-12-17 20:10:00 | 000,024,576 | ---- | M] () -- C:\Documents and Settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
PRC - [2009-10-24 03:47:58 | 000,409,096 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\WinAVAlarm.exe
PRC - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\3dm2.exe
PRC - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
PRC - [2009-10-16 18:37:22 | 001,325,936 | ---- | M] (Seagate) -- C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
PRC - [2009-03-25 15:32:18 | 000,102,400 | ---- | M] (LSI) -- C:\Program Files\MegaRAID Storage Manager\MegaPopup\popup.exe
PRC - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
PRC - [2009-03-02 11:27:10 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\MegaRAID Storage Manager\JRE\bin\javaw.exe
PRC - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008-04-13 17:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe
PRC - [2007-01-31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2002-10-15 18:00:20 | 001,818,624 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS\mixer.exe
PRC - [2000-04-05 16:03:10 | 000,388,096 | ---- | M] (Meikel.com) -- C:\Program Files\FreeMem Standard\freemem.exe


========== Modules (No Company Name) ==========

MOD - [2010-03-15 11:28:24 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009-12-17 20:10:00 | 000,024,576 | ---- | M] () -- C:\Documents and Settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
MOD - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
MOD - [2008-11-17 12:11:04 | 000,138,296 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\CIMPlugin.dll
MOD - [2008-11-17 12:11:00 | 002,034,792 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegcommon.dll
MOD - [2008-11-17 12:11:00 | 000,273,512 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegclient.dll
MOD - [2008-11-17 12:11:00 | 000,146,544 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegslp_client.dll
MOD - [2008-11-17 12:11:00 | 000,089,200 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegexportserver.dll
MOD - [2008-11-17 12:11:00 | 000,068,712 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\peglistener.dll
MOD - [2008-11-17 12:10:58 | 000,138,336 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\storelibirjni.dll
MOD - [2008-11-17 12:10:54 | 000,142,432 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\storelibjni.dll
MOD - [2008-11-17 12:10:52 | 000,068,704 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\Authenticate.dll
MOD - [2008-05-12 19:52:06 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\AlertStrings.dll
MOD - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\UPS\upsman\upsman.exe -- (UPSMan)
SRV - File not found [Auto | Stopped] -- C:\WINDOWS\system32\svrwsc.exe -- (SvrWsc)
SRV - [2012-04-17 20:10:22 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) [Auto | Running] -- C:\WINDOWS\system32\LxrSII1s.exe -- (LxrSII1s)
SRV - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] () [Auto | Running] -- C:\Program Files\AMCC\3DM2/3dm2.exe -- (3DM2)
SRV - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) [Auto | Running] -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (SgtSch2Svc)
SRV - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe -- (MegaMonitorSrv)
SRV - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe -- (MSMFramework)
SRV - [2007-01-31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2003-03-03 13:33:40 | 000,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- c:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\Mach3.sys -- (Mach3)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\root\LOCALS~1\Temp\AMDPCI.sys -- (AMDPCI)
DRV - [2011-04-19 17:06:32 | 000,167,584 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\snapman.sys -- (snapman)
DRV - [2011-04-01 21:30:32 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\timntr.sys -- (timounter)
DRV - [2011-04-01 21:30:32 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2011-04-01 21:30:14 | 000,368,480 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\tdrpman.sys -- (tdrpman)
DRV - [2010-06-02 16:05:02 | 000,109,184 | R--- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\symmpi.sys -- (Symmpi)
DRV - [2009-12-30 10:36:56 | 000,063,448 | ---- | M] (Lexar Media, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LxrSII1d.sys -- (LxrSII1d)
DRV - [2009-06-01 13:36:34 | 000,082,432 | ---- | M] (AMCC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\3wareDrv.sys -- (3wareDrv)
DRV - [2009-05-06 08:59:12 | 004,069,376 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009-02-20 19:09:16 | 000,044,032 | R--- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GigasetGenericUSB.sys -- (GigasetGenericUSB)
DRV - [2008-04-13 11:56:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008-04-13 11:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008-01-02 11:07:06 | 001,404,544 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmudax3.sys -- (cmuda3)
DRV - [2007-07-20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006-11-22 10:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2004-06-29 14:25:26 | 000,007,680 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\dontgo.sys -- (dontgo)
DRV - [2004-06-24 18:37:52 | 000,826,752 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmudau.sys -- (cmudau)
DRV - [2002-11-18 15:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002-09-16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001-08-17 12:49:00 | 000,075,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpae.sys -- (atirage3)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.ebay.com/...www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....erify2?&.src=ym
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{2A696BCE-44CF-45a4-B905-59CDFA08531A}: "URL" = http://del.icio.us/s...Terms}&type=all
IE - HKCU\..\SearchScopes\{7B3A7E4E-375E-41FE-B8EC-8D9CCE30AE37}: "URL" = http://search.avg.co...}&ychte=aa&nt=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 184.72.147.41:3128
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = 192.168.222.111


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: D:\canon prog\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files\DAP\DAPFireFox [2011-02-17 00:52:34 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2004-08-04 12:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {78875F5C-A685-4405-8DC5-D48DC65452B0} - No CLSID value found.
O2 - BHO: (Download Accelerator Plus Integration) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\DAP\dapieloader.dll (SpeedBit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [C-Media Speaker Configuration] F:\Cmi8738-6ch\Setup.exe /SPEAKER File not found
O4 - HKLM..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd File not found
O4 - HKLM..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Popup] C:\Program Files\MegaRAID Storage Manager\MegaPopup\Popup.exe (LSI)
O4 - HKLM..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [WinAVAlarm] C:\Program Files\AMCC\3DM2\WinAVAlarm.exe (LSI)
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [FreeMem Pro] C:\Program Files\FreeMem Standard\freemem.exe (Meikel.com)
O4 - HKCU..\Run: [LxrAutorun] C:\Documents and Settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe ()
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_2_202_233_ActiveX.exe (Adobe Systems Incorporated)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKCU\..Trusted Ranges: Range2 ([http] in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range3 ([http] in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 196.1.69.98 196.1.69.99
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AAC6870A-D985-48FE-9B39-E7D3F8DC8A21}: DhcpNameServer = 196.1.69.98 196.1.69.99
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-06-15 07:41:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell - "" = AutoRun
O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell\AutoRun\command - "" = E:\Windows\CHECK\DriveNavigator.exe
O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell\AutoRun\command - "" = F:\TYANCD.exe
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\AutoRun\command - "" = selomoje\\sranje.exe
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\explore\command - "" = selomoje\\\sranje.exe
O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\open\command - "" = selomoje\\\sranje.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 90 Days ==========

[2012-05-09 23:11:01 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
[2012-05-09 03:19:07 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\root\Recent
[2012-05-04 21:05:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3_files
[2012-04-24 23:50:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-04-23 00:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012-04-23 00:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012-04-23 00:30:17 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2012-04-23 00:30:17 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2012-04-23 00:30:17 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2012-04-23 00:30:17 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2012-04-23 00:30:17 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2012-04-23 00:30:06 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012-04-21 19:23:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Application Data\ZoomBrowser EX
[2012-04-21 15:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2012-04-21 15:06:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2012-04-18 23:46:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Local Settings\Application Data\CANON_INC
[2012-04-18 21:52:20 | 015,659,960 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\root\My Documents\Windows-KB890830-V4.7.exe
[2012-04-13 00:18:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2012-04-11 01:13:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2012-04-06 09:51:41 | 000,418,464 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012-04-05 00:33:28 | 000,000,000 | ---D | C] -- C:\Program Files\FreeMem Standard
[2012-04-05 00:33:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Start Menu\Programs\FreeMem Standard
[2012-04-01 00:07:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Local Settings\Application Data\Identities
[2012-03-29 21:10:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Desktop\for bahzad
[2012-03-29 00:19:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Start Menu\Programs\Nissin Di866
[2012-03-29 00:19:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Local Settings\Application Data\Deployment
[2012-03-29 00:00:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Local Settings\Application Data\Adobe
[2012-03-23 20:19:09 | 000,909,088 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\root\Desktop\JavaSetup6u31.exe
[2012-03-20 23:32:53 | 000,060,928 | ---- | C] (Totusoft) -- C:\Documents and Settings\root\My Documents\LAN_SpeedTest.exe
[2012-03-14 10:23:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2012-02-29 17:10:16 | 000,148,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imagehlp.dll
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 90 Days ==========

[2012-05-10 23:10:02 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-05-10 22:19:24 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job
[2012-05-09 03:28:56 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-05-09 03:19:34 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-05-09 03:18:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-05-09 03:18:52 | 000,178,544 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2012-05-09 03:18:48 | 000,101,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012-05-08 17:55:46 | 029,570,446 | ---- | M] () -- C:\Documents and Settings\root\Desktop\eos5dmkiii-im2-c-en.pdf
[2012-05-07 19:40:22 | 000,000,070 | ---- | M] () -- C:\Documents and Settings\root\default.pls
[2012-05-07 19:40:18 | 000,000,230 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012-05-06 18:49:02 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
[2012-05-06 07:52:44 | 000,001,919 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012-05-05 14:05:36 | 010,964,035 | ---- | M] () -- C:\Documents and Settings\root\Desktop\190O0065.JPG
[2012-05-04 21:14:26 | 000,034,919 | ---- | M] () -- C:\Documents and Settings\root\Desktop\print1_cwlke.pdf
[2012-05-04 21:11:26 | 000,026,065 | ---- | M] () -- C:\Documents and Settings\root\Desktop\Snoopy001_18_zacld.pdf
[2012-05-04 21:06:10 | 000,054,725 | ---- | M] () -- C:\Documents and Settings\root\Desktop\powerpuff_girls1_yfjcs.pdf
[2012-05-04 21:05:36 | 000,002,521 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3.htm
[2012-05-02 00:03:44 | 001,556,821 | ---- | M] () -- C:\Documents and Settings\root\My Documents\ecb350.pdf
[2012-05-01 22:26:52 | 002,012,180 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Clik%202011%20Gear%20Set%20Print.pdf
[2012-04-28 03:36:50 | 002,957,829 | ---- | M] () -- C:\Documents and Settings\root\My Documents\EOS-1Ds-MkII-Whitepaper.pdf
[2012-04-23 00:30:10 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deployJava1.dll
[2012-04-23 00:30:10 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2012-04-23 00:30:10 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2012-04-23 00:30:10 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2012-04-23 00:30:10 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl
[2012-04-21 15:06:36 | 000,000,594 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:14 | 000,000,461 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-21 07:22:26 | 004,515,558 | ---- | M] () -- C:\Documents and Settings\root\My Documents\canon EOS_1Ds_MarkII user guide.pdf
[2012-04-21 07:15:00 | 009,150,824 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Digital Cameras, Canon EOS-1Ds Mark II Digital Camera Test Image.mht
[2012-04-20 16:42:06 | 000,009,830 | ---- | M] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:02 | 000,393,808 | ---- | M] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:12 | 000,000,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-18 21:52:22 | 015,659,960 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\root\My Documents\Windows-KB890830-V4.7.exe
[2012-04-17 20:10:20 | 000,418,464 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012-04-17 20:10:20 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012-04-17 07:15:10 | 000,337,174 | ---- | M] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-15 23:17:24 | 000,019,454 | ---- | M] () -- C:\Documents and Settings\root\My Documents\cc_20120415_231710.reg
[2012-04-13 00:31:20 | 001,742,408 | ---- | M] () -- C:\WINDOWS\System32\MRT.exe
[2012-04-12 22:58:38 | 000,000,000 | ---- | M] () -- C:\WINDOWS\vpd.properties
[2012-04-11 16:14:42 | 002,148,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ntoskrnl.exe
[2012-04-11 16:14:42 | 002,148,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2012-04-11 16:12:06 | 001,862,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\win32k.sys
[2012-04-11 16:12:06 | 001,862,272 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2012-04-11 16:10:58 | 002,192,640 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2012-04-11 15:35:52 | 002,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2012-04-11 15:35:52 | 002,026,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2012-04-11 15:35:52 | 002,026,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ntkrnlpa.exe
[2012-04-11 01:08:14 | 032,966,016 | ---- | M] (CANON INC.) -- C:\Documents and Settings\root\My Documents\eu281en.exe
[2012-04-06 22:40:40 | 000,103,936 | ---- | M] () -- C:\Documents and Settings\root\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-03-30 02:55:50 | 000,019,952 | ---- | M] () -- C:\Documents and Settings\root\My Documents\cc_20120330_025543.reg
[2012-03-28 08:02:42 | 008,191,178 | ---- | M] () -- C:\Documents and Settings\root\Desktop\dslrp232.exe
[2012-03-26 23:03:46 | 000,000,151 | ---- | M] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2012-03-23 20:21:20 | 000,909,088 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\root\Desktop\JavaSetup6u31.exe
[2012-03-23 02:32:00 | 034,066,685 | ---- | M] () -- C:\Documents and Settings\root\Desktop\Canon EOS Utility 2.5.1.1.exe
[2012-03-20 23:32:54 | 000,060,928 | ---- | M] (Totusoft) -- C:\Documents and Settings\root\My Documents\LAN_SpeedTest.exe
[2012-03-02 06:01:32 | 011,082,752 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2012-03-01 14:01:32 | 005,978,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2012-03-01 14:01:32 | 002,000,384 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iertutil.dll
[2012-03-01 14:01:32 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcpl.cpl
[2012-03-01 14:01:32 | 001,469,440 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2012-03-01 14:01:32 | 001,212,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\urlmon.dll
[2012-03-01 14:01:32 | 000,916,992 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wininet.dll
[2012-03-01 14:01:32 | 000,743,424 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedvtool.dll
[2012-03-01 14:01:32 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mstime.dll
[2012-03-01 14:01:32 | 000,611,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstime.dll
[2012-03-01 14:01:32 | 000,602,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeeds.dll
[2012-03-01 14:01:32 | 000,602,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeeds.dll
[2012-03-01 14:01:32 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iedkcs32.dll
[2012-03-01 14:01:32 | 000,387,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2012-03-01 14:01:32 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\occache.dll
[2012-03-01 14:01:32 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iepeers.dll
[2012-03-01 14:01:32 | 000,184,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\iepeers.dll
[2012-03-01 14:01:32 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\url.dll
[2012-03-01 14:01:32 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\url.dll
[2012-03-01 14:01:32 | 000,066,560 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtmled.dll
[2012-03-01 14:01:32 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msfeedsbs.dll
[2012-03-01 14:01:32 | 000,055,296 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2012-03-01 14:01:32 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\licmgr10.dll
[2012-03-01 14:01:32 | 000,043,520 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\licmgr10.dll
[2012-03-01 14:01:32 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\jsproxy.dll
[2012-03-01 14:01:32 | 000,025,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\jsproxy.dll
[2012-02-29 17:10:16 | 000,177,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wintrust.dll
[2012-02-29 17:10:16 | 000,148,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\imagehlp.dll
[2012-02-29 15:17:40 | 000,385,024 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\html.iec
[2012-02-29 15:17:40 | 000,174,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ie4uinit.exe
[2012-02-29 15:17:40 | 000,174,080 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ie4uinit.exe
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-05-08 17:51:01 | 029,570,446 | ---- | C] () -- C:\Documents and Settings\root\Desktop\eos5dmkiii-im2-c-en.pdf
[2012-05-08 06:39:06 | 010,964,035 | ---- | C] () -- C:\Documents and Settings\root\Desktop\190O0065.JPG
[2012-05-04 21:14:27 | 000,034,919 | ---- | C] () -- C:\Documents and Settings\root\Desktop\print1_cwlke.pdf
[2012-05-04 21:11:28 | 000,026,065 | ---- | C] () -- C:\Documents and Settings\root\Desktop\Snoopy001_18_zacld.pdf
[2012-05-04 21:06:15 | 000,054,725 | ---- | C] () -- C:\Documents and Settings\root\Desktop\powerpuff_girls1_yfjcs.pdf
[2012-05-04 21:05:33 | 000,002,521 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3.htm
[2012-05-02 00:03:43 | 001,556,821 | ---- | C] () -- C:\Documents and Settings\root\My Documents\ecb350.pdf
[2012-05-01 22:26:51 | 002,012,180 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Clik%202011%20Gear%20Set%20Print.pdf
[2012-04-28 03:36:48 | 002,957,829 | ---- | C] () -- C:\Documents and Settings\root\My Documents\EOS-1Ds-MkII-Whitepaper.pdf
[2012-04-25 00:00:56 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-04-24 23:51:03 | 000,001,919 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012-04-24 23:50:57 | 000,001,651 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-04-21 15:06:34 | 000,000,594 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:12 | 000,000,461 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-21 07:22:25 | 004,515,558 | ---- | C] () -- C:\Documents and Settings\root\My Documents\canon EOS_1Ds_MarkII user guide.pdf
[2012-04-21 07:14:58 | 009,150,824 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Digital Cameras, Canon EOS-1Ds Mark II Digital Camera Test Image.mht
[2012-04-20 16:43:08 | 000,009,830 | ---- | C] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:00 | 000,393,808 | ---- | C] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:11 | 000,000,443 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-17 07:15:04 | 000,337,174 | ---- | C] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-15 23:17:13 | 000,019,454 | ---- | C] () -- C:\Documents and Settings\root\My Documents\cc_20120415_231710.reg
[2012-04-06 09:51:41 | 000,000,830 | ---- | C] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-04-05 00:33:28 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\GkSui16.EXE
[2012-03-30 02:55:46 | 000,019,952 | ---- | C] () -- C:\Documents and Settings\root\My Documents\cc_20120330_025543.reg
[2012-03-28 08:02:31 | 008,191,178 | ---- | C] () -- C:\Documents and Settings\root\Desktop\dslrp232.exe
[2012-03-23 02:30:26 | 034,066,685 | ---- | C] () -- C:\Documents and Settings\root\Desktop\Canon EOS Utility 2.5.1.1.exe
[2012-03-23 00:08:57 | 040,378,518 | ---- | C] () -- C:\Documents and Settings\root\Desktop\big_buck_bunny_240_stereo_x264.mp4
[2012-02-16 06:51:36 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012-02-16 06:51:36 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2011-07-12 09:27:54 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011-06-27 19:30:52 | 000,002,828 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2011-06-26 14:35:48 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\5B3206E10A.sys
[2010-11-11 11:45:58 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\ScsiOat.dll
[2010-10-08 20:16:46 | 000,000,093 | ---- | C] () -- C:\WINDOWS\WFT-E5Utility.INI
[2010-10-03 10:18:19 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010-09-22 05:24:26 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ICOMP.EXE
[2010-09-11 09:41:26 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2010-08-22 23:02:09 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-08-19 16:47:18 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\root\Application Data\$_hpcst$.hpc
[2010-08-18 23:39:52 | 000,000,171 | ---- | C] () -- C:\Documents and Settings\root\Application Data\default.rss
[2010-08-18 23:39:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\root\Application Data\downloads.m3u
[2010-08-17 20:52:06 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\CMRMDRV3.dll
[2010-08-15 07:04:35 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2010-08-15 07:03:21 | 000,479,232 | ---- | C] () -- C:\WINDOWS\System32\Cmeaupci.exe
[2010-08-15 07:03:21 | 000,000,379 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfl
[2010-08-15 07:02:57 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\CmiInstallResAll.dll
[2010-08-15 07:02:57 | 000,003,091 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfg
[2010-08-15 07:02:57 | 000,000,215 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.imi
[2010-08-15 07:02:56 | 000,000,779 | ---- | C] () -- C:\WINDOWS\cmudax3.ini
[2010-08-10 18:37:14 | 000,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2010-07-11 18:20:38 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CmiUSB2Uninstall.exe
[2010-06-30 21:03:01 | 000,000,230 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010-06-27 01:35:33 | 000,002,162 | ---- | C] () -- C:\WINDOWS\Cmudau.ini
[2010-06-27 01:05:53 | 000,000,057 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2010-06-24 23:16:10 | 000,232,840 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.exe
[2010-06-24 23:16:10 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.dll
[2010-06-24 20:51:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010-06-24 15:49:37 | 000,001,150 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2010-06-23 23:58:29 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2010-06-23 22:53:12 | 000,000,112 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2010-06-23 22:53:12 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2010-06-23 22:52:05 | 000,000,246 | ---- | C] () -- C:\WINDOWS\System32\dl.exe
[2010-06-23 07:48:52 | 000,103,936 | ---- | C] () -- C:\Documents and Settings\root\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-06-22 23:06:43 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-06-22 23:06:43 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-06-16 00:27:49 | 001,742,408 | ---- | C] () -- C:\WINDOWS\System32\MRT.exe
[2010-06-15 07:46:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-06-15 07:38:00 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-06-15 07:30:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-06-15 07:29:30 | 000,101,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2010-07-01 23:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010-07-18 19:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gigaset QuickSync
[2010-07-18 20:04:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cached Installations
[2010-08-10 13:02:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2010-09-14 21:12:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grass Valley
[2010-09-14 21:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canopus
[2010-10-10 08:40:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010-10-16 12:07:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AMCC
[2011-02-08 17:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011-02-17 00:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2011-03-15 08:19:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011-03-17 22:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolarWinds
[2011-04-01 21:30:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2011-10-05 22:49:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ClubSanDisk
[2011-10-23 00:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PassMark
[2012-04-21 15:33:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2010-11-23 06:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\HD Tune Pro
[2011-01-06 21:17:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\Eye-Fi
[2011-01-06 21:28:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\fi.eye.center.E430518E652B889A80EC0E8A6E532C09FF36DF62.1
[2011-07-06 20:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\AVG9
[2012-05-10 22:19:24 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job

----------

OTL Extras logfile created on: 10-5-12 11:10:30 PM - Run 1
OTL by OldTimer - Version 3.2.42.2 Folder = C:\Documents and Settings\root\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-M-yy

3.00 Gb Total Physical Memory | 2.02 Gb Available Physical Memory | 67.51% Memory free
4.84 Gb Paging File | 4.01 Gb Available in Paging File | 82.72% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.29 Gb Total Space | 6.69 Gb Free Space | 36.57% Space Free | Partition Type: FAT32
Drive D: | 96.71 Gb Total Space | 71.25 Gb Free Space | 73.67% Space Free | Partition Type: FAT32
Drive L: | 465.75 Gb Total Space | 463.25 Gb Free Space | 99.46% Space Free | Partition Type: NTFS
Drive M: | 68.36 Gb Total Space | 35.10 Gb Free Space | 51.34% Space Free | Partition Type: NTFS

Computer Name: TYANS2469 | User Name: root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\WINDOWS\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\WINDOWS\System32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\WINDOWS\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\WINDOWS\System32\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\WINDOWS\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\WINDOWS\System32\WScript.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "C:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
helpfile [open] -- winhlp32.exe %1 (Microsoft Corporation)
hlpfile [open] -- %SystemRoot%\System32\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\WINDOWS\system32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 (Microsoft Corporation)
wsffile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 (Microsoft Corporation)
wshfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [Digital Photo Professional] -- C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 4

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\System32\mmc.exe" = C:\WINDOWS\System32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)
"D:\Program Files\Nero\Nero 9\Nero ShowTime\ShowTime.exe" = D:\Program Files\Nero\Nero 9\Nero ShowTime\ShowTime.exe:*:Enabled:Nero ShowTime -- (Nero Software AG)
"E:\e\Program Files\Phone\Skype.exe" = E:\e\Program Files\Phone\Skype.exe:*:Enabled:Skype
"C:\Program Files\MegaRAID Storage Manager\MegaPopup\popup.exe" = C:\Program Files\MegaRAID Storage Manager\MegaPopup\popup.exe:*:Enabled:popup -- (LSI)
"C:\Program Files\MegaRAID Storage Manager\JRE\bin\javaw.exe" = C:\Program Files\MegaRAID Storage Manager\JRE\bin\javaw.exe:*:Enabled:Java™ Platform SE binary -- (Sun Microsystems, Inc.)
"C:\Program Files\Eye-Fi\Helper\EyeFiHelper.exe" = C:\Program Files\Eye-Fi\Helper\EyeFiHelper.exe:*:Enabled:Eye-Fi Helper -- (Eye-Fi, Inc.)
"C:\Program Files\Go2PC Anywhere\Go2PCAnywhere.exe" = C:\Program Files\Go2PC Anywhere\Go2PCAnywhere.exe:*:Enabled:Go2PC Anywhere
"D:\Program Files\Phone\Skype.exe" = D:\Program Files\Phone\Skype.exe:*:Enabled:Skype -- (Skype Technologies S.A.)
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0711500B-9912-4D60-9A49-C577B4503D42}" = Nero Recode Help
"{07FF7593-9DEA-40B5-9F87-F557E65BBF60}" = Nero Recode
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{1122AAC4-AAAA-43BF-B2D4-3C8C12378952}" = Nero InfoTool
"{11A84FCA-C3C7-4AFD-A797-111DB8569DBC}" = Nero BurningROM
"{12345674-DE9A-677A-CCEE-666356D89777}" = Nero BurnRights
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1B040683-C390-4711-ABC7-DA8D85E470E7}" = NeroBurningROM
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{2C4E30D8-38B5-479A-B996-956655FA8ED7}" = Eye-Fi Helper 3.2
"{2D3455A8-3B15-41A8-99F8-0D4215746463}" = Nero StartSmart
"{3097B151-1F61-4211-A4CC-D70127B226AE}" = SoundTrax
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F30CC51-0788-487B-AA83-7214A239C0C0}" = Nero Disc Copy Gadget Help
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{49235EC7-BC4F-45A7-9F65-3486AC03E45E}" = MegaRAID Storage Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{548F99E0-14CC-4D53-A7D6-4A62A5F2C748}" = Nero PhotoSnap
"{56BE5CC9-95E6-4128-ABEA-968414CA9C80}" = DolbyFiles
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5BFB8A64-70EA-DE36-6BC3-7039D2E00F75}" = Eye-Fi Center
"{5C2E8A0F-80E2-4C68-8CC0-D8D16E7196BF}" = Nero RescueAgent Help
"{5C42EAB8-54F9-423A-948C-1CBEF25F8DB4}" = Nero PhotoSnap Help
"{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.2
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{62369F2F77534556AEF4C58152E3BDE5}" = Dr.DivX
"{69ca421c-df86-4f53-bb4e-d8c821382179}" = Nero 9
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72D01427-57EC-4179-815C-18ED0D461107}" = ATI AVIVO Codecs
"{75321954-2589-11DC-DDCC-E98356D81493}" = Nero DriveSpeed
"{753973C4-B961-43BF-B2D4-3C8C92F7216E}" = Nero DriveSpeed
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Pro
"{7b7e564b-0c70-4506-9ab6-b7a2044425ab}" = Gigaset QuickSync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C654BD0-1949-43DE-84F2-EC2A1ABB0CB4}" = Nero ShowTime
"{943CC0C0-2253-4FE0-9493-DD386F7857FD}" = Nero Express
"{948FFAAE-C57F-447B-9B07-3721E950BFDC}" = Nero ShowTime
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{99052DB7-9592-4522-A558-5417BBAD48EE}" = Microsoft ActiveSync
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A73BEC3C-40A0-480E-87EF-EFCD33629088}" = NeroExpress
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AAA12554-2589-11DC-92EF-E98356D81493}" = Nero InfoTool
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AC76BA86-7AD7-5A76-5A64-7E8A45000001}" = Adobe Reader Japanese Fonts
"{B2C12C8D-65DC-40BD-B309-5ADB0C6C8D8F}" = Nero WaveEditor
"{B2C85224-88C1-4ED2-8ECC-EF7362D9F63B}" = Movie Templates - Pack 1
"{B96C2601-52F5-4D5D-816A-63469EA311EF}" = "Nero SoundTrax Help
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{BCD82AB5-670D-4242-90FA-1F97103C16CD}" = Movie Templates - Starter Kit
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C43E4B9C-14C8-4EB0-998B-85211B6EDD61}" = Seagate DiscWizard
"{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}" = Menu Templates - Starter Kit
"{CD1826A5-CFCC-4C6E-9F9D-E181876162EA}" = Nero Rescue Agent
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D7C206B6-1A63-4389-A8B1-8F607D0BFF1F}" = Nero StartSmart Help
"{E4A8DD87-A746-4443-BF25-CAF99CED6767}" = Nero Disc Copy Gadget
"{E86156E5-9859-440D-8876-26CED1349802}" = Nero WaveEditor Help
"{EA9FFE54-D8B1-11DC-92EF-E98356D81493}" = Nero BurnRights
"{F53F6769-AC46-49E3-ABE3-2C8AFD39D0DD}" = Nero Vision
"32fsu32_is1" = File Scavenger 3.2 (English)
"358CC050FAD9417859342EF624B40681F89D2C54" = Windows Driver Package - LSI Logic System (11/14/2002 6.2.0)
"8c793da9f0aa7e94d3b4faba721006ff-1001563592" = 3ware Disk Management Tools
"99411784F82301A93B4435816C2D5BB25134E603" = Windows Driver Package - LSI Logic (SYMMPI) SCSIAdapter (08/16/2005 1.21.03.00)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"Bulk Rename Utility_is1" = Bulk Rename Utility 2.7.1.2
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX
"CameraWindowLauncher" = Canon Utilities CameraWindow
"CANON iMAGE GATEWAY Task" = CANON iMAGE GATEWAY Task for ZoomBrowser EX
"Canon Internet Library for ZoomBrowser EX" = Canon Internet Library for ZoomBrowser EX
"Canon MOV Decoder" = Canon MOV Decoder
"Canon MOV Encoder" = Canon MOV Encoder
"CCleaner" = CCleaner
"C-Media PCI Sound" = C-Media PCI Audio
"C-Media USB Sound" = 510EX USB 5.1 SOUND EXPERT EXTERNAL
"CSCLIB" = Canon Camera Support Core Library
"Di866 DM Startup" = Di866 DM Startup 1.0
"DivX Setup.divx.com" = DivX Setup
"divxh264_is1" = DivX H.264 decoder 8.2.0.26
"Download Accelerator Plus (DAP)" = Download Accelerator Plus (DAP)
"DPP" = Canon Utilities Digital Photo Professional 3.9
"EOS Utility" = Canon Utilities EOS Utility
"EPC_DeinstKey" = Saab EPC
"ffdshow_is1" = ffdshow v1.1.3562 [2010-09-07]
"fi.eye.center.E430518E652B889A80EC0E8A6E532C09FF36DF62.1" = Eye-Fi Center
"FreeMem Standard" = FreeMem Standard
"HD Tune_is1" = HD Tune 2.55
"HP Deskjet 6500 Series_Driver" = HP Deskjet 6500 Series
"ie8" = Windows Internet Explorer 8
"InstallShield_{49235EC7-BC4F-45A7-9F65-3486AC03E45E}" = MegaRAID Storage Manager v2.92-02
"InstallShield_{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PowerQuest PartitionMagic 8.0
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"LanSpy_is1" = LanSpy
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Client" = Microsoft Security Essentials
"MovieEditTask" = Canon MovieEdit Task for ZoomBrowser EX
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MyCamera" = Canon Utilities MyCamera
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroVision!UninstallKey" = Nero Digital
"Original Data Security Tools" = Canon Utilities Original Data Security Tools
"PCI Audio Driver" = PCI Audio Driver
"PhotoStitch" = Canon Utilities PhotoStitch
"Picture Style Editor" = Canon Utilities Picture Style Editor
"PROSet" = Intel® PRO Network Adapters and Drivers
"QueTek File Scavenger 3.2 (en)" = File Scavenger 3.2 (en)
"RemoteCaptureTask" = Canon Utilities RemoteCapture Task for ZoomBrowser EX
"ST6UNST #1" = FileSync
"VLC media player" = VLC media player 1.1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1" = Xvid 1.2.2 final uninstall
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX
"ZoomBrowser EX Memory Card Utility" = Canon ZoomBrowser EX Memory Card Utility

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"71cdbdf800bad043" = Nissin Di866

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 06-5-12 12:52:35 AM | Computer Name = TYANS2469 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 06-5-12 12:52:43 AM | Computer Name = TYANS2469 | Source = Microsoft Security Client Setup | ID = 100
Description = HRESULT:0x8004FF11 Description:. 0x8004FF11.

Error - 06-5-12 12:52:43 AM | Computer Name = TYANS2469 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 06-5-12 8:38:23 AM | Computer Name = TYANS2469 | Source = Application Error | ID = 1000
Description = Faulting application msconfig.exe, version 5.1.2600.5512, faulting
module comctl32.dll, version 6.0.2900.6028, fault address 0x00007901.

Error - 06-5-12 8:38:31 AM | Computer Name = TYANS2469 | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 06-5-12 8:40:53 AM | Computer Name = TYANS2469 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 06-5-12 8:45:32 AM | Computer Name = TYANS2469 | Source = Application Error | ID = 1000
Description = Faulting application msconfig.exe, version 5.1.2600.5512, faulting
module comctl32.dll, version 6.0.2900.6028, fault address 0x00007901.

Error - 06-5-12 8:45:37 AM | Computer Name = TYANS2469 | Source = Application Error | ID = 1000
Description = Faulting application drwtsn32.exe, version 5.1.2600.0, faulting module
dbghelp.dll, version 5.1.2600.5512, fault address 0x0001295d.

Error - 06-5-12 10:25:17 AM | Computer Name = TYANS2469 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 06-5-12 7:10:17 PM | Computer Name = TYANS2469 | Source = Application Error | ID = 1000
Description = Faulting application FlashPlayerUpdateService.exe, version 11.2.202.233,
faulting module FlashPlayerUpdateService.exe, version 11.2.202.233, fault address
0x0000abfc.

[ System Events ]
Error - 09-5-12 2:16:57 AM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%854

Source
Path: http://go.microsoft....5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80096010 Error description: The digital
signature of the object did not verify.

Error - 09-5-12 2:16:57 AM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%854

Source
Path: http://go.microsoft....5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80096010 Error description: The digital
signature of the object did not verify.

Error - 09-5-12 12:45:40 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.

Error - 09-5-12 12:45:40 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.

Error - 09-5-12 8:33:06 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.

Error - 09-5-12 8:33:06 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%859 Update Stage: %%853

Source
Path: http://www.microsoft.com Signature Type: %%800 Update Type: %%803 User: NT AUTHORITY\SYSTEM

Current
Engine Version: Previous Engine Version: 0.0.0.0 Error code: 0x80240022 Error description:
The program can't check for definition updates.

Error - 09-5-12 8:36:28 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%854

Source
Path: http://go.microsoft....5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80096010 Error description: The digital
signature of the object did not verify.

Error - 09-5-12 8:36:28 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%854

Source
Path: http://go.microsoft....5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80096010 Error description: The digital
signature of the object did not verify.

Error - 09-5-12 8:36:28 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%854

Source
Path: http://go.microsoft....5D-99752CCA7094

Signature
Type: %%800 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80096010 Error description: The digital
signature of the object did not verify.

Error - 09-5-12 8:36:28 PM | Computer Name = TYANS2469 | Source = Microsoft Antimalware | ID = 2001
Description = %%860 has encountered an error trying to update signatures. New Signature
Version: Previous Signature Version: 0.0.0.0 Update Source: %%851 Update Stage: %%854

Source
Path: http://go.microsoft....5D-99752CCA7094

Signature
Type: %%801 Update Type: %%803 User: NT AUTHORITY\NETWORK SERVICE Current Engine Version:
Previous Engine Version: 0.0.0.0 Error code: 0x80096010 Error description: The digital
signature of the object did not verify.


< End of report >
  • 0

#4
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - File not found [Auto | Stopped] -- C:\WINDOWS\system32\svrwsc.exe -- (SvrWsc)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 184.72.147.41:3128
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4 - HKLM..\Run: [C-Media Speaker Configuration] F:\Cmi8738-6ch\Setup.exe /SPEAKER File not found
    O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell - "" = AutoRun
    O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\Shell\AutoRun\command - "" = E:\Windows\CHECK\DriveNavigator.exe
    O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell - "" = AutoRun
    O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\Shell\AutoRun\command - "" = F:\TYANCD.exe
    O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\AutoRun\command - "" = selomoje\\sranje.exe
    O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\explore\command - "" = selomoje\\\sranje.exe
    O33 - MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\Shell\open\command - "" = selomoje\\\sranje.exe
    [4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
    [1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [emptyflash]
    [createrestorepoint]
    [reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done


Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
  • 0

#5
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
OK, I made as you describe but after reboot i try to open the ComboFix.exe and "NSIS error" message come, I couldn't install it. I'll paste the note that open after reboot.

All processes killed
========== OTL ==========
Service SvrWsc stopped successfully!
Service SvrWsc deleted successfully!
File C:\WINDOWS\system32\svrwsc.exe not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\C-Media Speaker Configuration deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{192b5aee-5310-11e0-98da-00e081250736}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{192b5aee-5310-11e0-98da-00e081250736}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{192b5aee-5310-11e0-98da-00e081250736}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{192b5aee-5310-11e0-98da-00e081250736}\ not found.
File E:\Windows\CHECK\DriveNavigator.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6647fc20-7c91-11df-9298-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6647fc20-7c91-11df-9298-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6647fc20-7c91-11df-9298-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6647fc20-7c91-11df-9298-806d6172696f}\ not found.
File F:\TYANCD.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7cc7a56-7892-11df-acf6-806d6172696f}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7cc7a56-7892-11df-acf6-806d6172696f}\ not found.
File selomoje\\sranje.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7cc7a56-7892-11df-acf6-806d6172696f}\ not found.
File selomoje\\\sranje.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7cc7a56-7892-11df-acf6-806d6172696f}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7cc7a56-7892-11df-acf6-806d6172696f}\ not found.
File selomoje\\\sranje.exe not found.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET4.tmp deleted successfully.
C:\WINDOWS\SET8.tmp deleted successfully.
C:\WINDOWS\002830_.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\root\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\root\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 56502 bytes

User: All Users

User: NetworkService
->Temp folder emptied: 194590 bytes
->Temporary Internet Files folder emptied: 33237 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: root
->Temp folder emptied: 47075 bytes
->Temporary Internet Files folder emptied: 307850627 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 59622 bytes

User: Administrator
->Temp folder emptied: 160 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 56502 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9327653 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 128896478 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 39525271 bytes

Total Files Cleaned = 464.00 mb


[EMPTYFLASH]

User: Default User
->Flash cache emptied: 0 bytes

User: All Users

User: NetworkService

User: LocalService

User: root
->Flash cache emptied: 0 bytes

User: Administrator
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.42.2 log created on 05112012_020350

Files\Folders moved on Reboot...
C:\Documents and Settings\root\Local Settings\Temp\WCESLog.log moved successfully.
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\DSAML6PF\fastbutton[1].htm moved successfully.
C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\OLCQYVZQ\page__gopid__2155334[1].htm moved successfully.
File\Folder C:\Documents and Settings\root\Local Settings\Temporary Internet Files\Content.IE5\2PGDT0CH\q'·/ܱ_.0 not found!
File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot.
C:\WINDOWS\temp\MpCmdRun.log moved successfully.

Registry entries deleted on Reboot...
  • 0

#6
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
OK now. I did make it work, just download and run. and it's work. this is the report form ComboFix.exe :



ComboFix 12-05-10.04 - root 11-05-12 2:49.1.2 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2582 [GMT 3:00]
Running from: A:\ComboFix_1.exe
AV: Microsoft Security Essentials *Enabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\2B11E0DF.TMP
c:\documents and settings\All Users\Application Data\TEMP\5A775C3F.TMP
c:\documents and settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
c:\documents and settings\root\WINDOWS
d:\program files\epc\MSMAsk32.ocx
.
c:\windows\system32\wuauclt.exe . . . is infected!!
.
c:\windows\system32\regsvr32.exe . . . is infected!!
.
c:\windows\system32\wscntfy.exe . . . is infected!!
.
.
((((((((((((((((((((((((( Files Created from 2012-04-10 to 2012-05-10 )))))))))))))))))))))))))))))))
.
.
2012-05-10 23:03 . 2012-05-10 23:03 -------- d-----w- C:\_OTL
2012-05-06 04:49 . 2012-05-06 04:49 -------- d-----w- c:\documents and settings\Administrator
2012-04-24 20:50 . 2012-04-24 20:50 -------- d-----w- c:\program files\Microsoft Security Client
2012-04-22 21:30 . 2012-04-22 21:30 -------- d-----w- c:\program files\Common Files\Java
2012-04-22 21:30 . 2012-04-22 21:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-22 21:30 . 2012-04-22 21:30 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-22 21:30 . 2012-04-22 21:30 -------- d-----w- c:\program files\Java
2012-04-21 16:23 . 2012-04-21 16:23 -------- d-----w- c:\documents and settings\root\Application Data\ZoomBrowser EX
2012-04-21 12:33 . 2012-04-21 12:33 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoStitch
2012-04-21 12:06 . 2012-04-21 12:06 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2012-04-18 20:46 . 2012-04-18 20:46 -------- d-----w- c:\documents and settings\root\Local Settings\Application Data\CANON_INC
2012-04-17 17:10 . 2012-04-17 17:10 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-17 17:10 . 2012-04-06 06:51 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-17 17:10 . 2011-05-19 14:24 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-11 13:14 . 2004-08-04 09:00 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 13:12 . 2004-08-04 09:00 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 12:35 . 2004-08-03 19:59 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-20 17:44 . 2012-03-20 17:44 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-01 11:01 . 2004-08-04 19:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-03-01 11:01 . 2004-08-04 09:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01 . 2004-08-04 09:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-02-29 14:10 . 2004-08-04 09:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2004-08-04 09:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2004-08-04 09:00 385024 ----a-w- c:\windows\system32\html.iec
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-07-11 . ECCCBFFC9B08306C57A535809A05E5CA . 46924 . . [7.4.7600.226] . . c:\windows\system32\wuauclt.exe
[-] 2010-06-21 . 5B5A45A52491E009715EE680B1770AB1 . 110888 . . [5.4.3790.2180] . . c:\windows\$NtServicePackUninstall$\wuauclt.exe
[-] 2010-06-21 . 16A492BFD3E5EFE041151E1D04E17D73 . 110872 . . [5.4.3790.5512] . . c:\windows\ServicePackFiles\i386\wuauclt.exe
.
[-] 2010-06-21 . 09E2D2EC83F83B59691DE3CB283C9BBF . 24416 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\userinit.exe
[-] 2010-06-21 . 16A1750C90C84815D6B4ABC5B9454B26 . 25936 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2010-06-21 . 16A1750C90C84815D6B4ABC5B9454B26 . 25936 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe
.
[-] 2010-06-21 . FC089B1716EDAD0531A1C7926811180C . 146096 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[-] 2010-06-21 . D52229773D26478F30559440C85D20CD . 146112 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\regedit.exe
[-] 2010-06-21 . FC089B1716EDAD0531A1C7926811180C . 146096 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\regedit.exe
.
[-] 2010-07-11 . 1432AACDF69334B9305F0E163DF75A11 . 13536 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
[-] 2010-06-21 . A03E215FF5CA42EA806BD48B39270929 . 13552 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe
[-] 2010-06-21 . 28345CC26F676AA1BD65E82562A3F23C . 13536 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
.
[-] 2010-06-21 . 8324B0E332BF0AA633143D66F9D848A5 . 93008 . . [6.00.2900.2180] . . c:\windows\ie8\iexplore.exe
[-] 2010-06-21 . 948357FA4AB362A4BBDA6852F1FC7886 . 92992 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\iexplore.exe
[-] 2010-06-21 . AE9E928A7CC7F2A96AC1C6D981005D19 . 632580 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2011-01-24 2200376]
"FreeMem Pro"="c:\program files\FreeMem Standard\freemem.exe" [2000-04-05 388096]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"C-Media Mixer"="Mixer.exe" [2002-10-15 1818624]
"WinAVAlarm"="c:\program files\AMCC\3DM2\WinAVAlarm.exe" [2009-10-24 409096]
"Popup"="c:\program files\MegaRAID Storage Manager\MegaPopup\Popup.exe" [2009-03-25 102400]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2009-10-16 1325936]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EPSI ToolBar.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EPSI ToolBar.lnk
backup=c:\windows\pss\EPSI ToolBar.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PhotoDiary for Sony HDPS.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PhotoDiary for Sony HDPS.lnk
backup=c:\windows\pss\PhotoDiary for Sony HDPS.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AvgUninstallURL]
start http://www.avg.com/w...=92&ver=9.0.894 [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
c:\windows\system32\WLTRAY [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2009-10-16 15:42 904840 ----a-w- c:\program files\Seagate\DiscWizard\TimounterMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-13 14:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-03-21 18:56 1230704 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2006-11-13 10:39 1289000 ----a-w- c:\program files\Microsoft ActiveSync\wcescomm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Seagate Scheduler2 Service]
2009-10-16 15:39 136544 ----a-w- c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\System32\\mmc.exe"=
"d:\\Program Files\\Nero\\Nero 9\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\MegaRAID Storage Manager\\MegaPopup\\popup.exe"=
"c:\\Program Files\\MegaRAID Storage Manager\\JRE\\bin\\javaw.exe"=
"c:\\Program Files\\Eye-Fi\\Helper\\EyeFiHelper.exe"=
"d:\\Program Files\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
.
R0 3wareDrv;3wareDrv;c:\windows\system32\drivers\3wareDrv.sys [16-10-10 12:05 PM 82432]
R0 dontgo;Promise Removable Disk Control Driver;c:\windows\system32\drivers\dontgo.sys [12-9-10 11:01 AM 7680]
R0 ulsata2;ulsata2;c:\windows\system32\drivers\ulsata2.sys [12-9-10 11:01 AM 108544]
R2 3DM2;3ware 3DM2;c:\program files\AMCC\3DM2\3dm2.exe [16-10-10 12:10 PM 1354248]
R2 LxrSII1d;Secure II Driver;c:\windows\system32\drivers\LxrSII1d.sys [14-12-10 2:55 PM 63448]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Common Files\Seagate\Schedule2\schedul2.exe [16-10-09 6:39 PM 431456]
S2 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [06-4-12 9:51 AM 253088]
S2 UPSMan;UPSMan;c:\program files\UPS\upsman\upsman.exe --> c:\program files\UPS\upsman\upsman.exe [?]
S3 GigasetGenericUSB;GigasetGenericUSB;c:\windows\system32\drivers\GigasetGenericUSB.sys [19-7-10 6:11 PM 44032]
S3 Mach3;Mach3 Pulseing Service;c:\windows\system32\Drivers\Mach3.sys --> c:\windows\system32\Drivers\Mach3.sys [?]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-10 c:\windows\Tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 10:52]
.
2012-05-10 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-06 17:10]
.
2012-05-10 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 14:03]
.
.
------- Supplementary Scan -------
.
uStart Page = https://login.yahoo....erify2?&.src=ym
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
TCP: DhcpNameServer = 196.1.69.98 196.1.69.99
Name-Space Handler: FTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
Name-Space Handler: HTTP\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - c:\progra~1\DAP\dapie.dll
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-LxrAutorun - c:\documents and settings\root\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
HKLM-Run-CmPCIaudio - CMICNFG3.cpl
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-11 02:57
Windows 5.1.2600 Service Pack 3 FAT NTAPI
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\3DM2]
"ImagePath"="c:\program files\AMCC\3DM2/3dm2.exe"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(916)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(972)
c:\windows\system32\relog_ap.dll
.
- - - - - - - > 'explorer.exe'(4068)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\Mixer.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\LxrSII1s.exe
c:\windows\system32\msiexec.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
c:\program files\MegaRAID Storage Manager\JRE\bin\javaw.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-05-11 02:59:31 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-10 23:59
.
Pre-Run: 8,488,796,160 bytes free
Post-Run: 8,387,919,872 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
.
- - End Of File - - 92CA54ED8391F37D34692FDB49CB7874
  • 0

#7
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
To use Virustotal go Here
Posted Image
  • Click the Choose File button in the middle of the screen. This will open a File Upload window.
  • In the File name box, type, or copy and paste the following and click Open: NOTE.. Only one file per scan
  • c:\windows\system32\wuauclt.exe
    c:\windows\system32\userinit.exe
    .
  • This will put the file in the box on the Virustotal page.
  • Click the Scan it! button and wait for the reply.
  • Copy and paste the Virustotal link(s) (URL) in your next reply
  • Repeat 1 through 6 for each file listed.

  • 0

#8
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
thank you gammo for your time and help. I scanned the files with the link for the following files:

c:\windows\system32\regsvr32.exe
https://www.virustot...sis/1336758370/

C:\WINDOWS\system32\userinit.exe
https://www.virustot...sis/1336757037/

c:\windows\system32\wuauclt.exe
https://www.virustot...sis/1336758324/
  • 0

#9
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Gammo, I need to get rest now, I'm having strong flu. I can't continue any more, I will continue tomorrow. take care and good night ;)
  • 0

#10
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
Run OTL
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the box that says Scan All Users.
  • Under the Custom Scan box paste this in


    /md5start
    wuauclt.exe
    userinit.exe
    regedit.exe
    wscntfy.exe
    iexplore.exe
    regsvr32.exe
    /md5stop


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time


Please give me an update on the problem as well.
  • 0

Advertisements


#11
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hi Gammo. only OTL.TXT show up with notepad.

OTL logfile created on: 12-5-12 2:51:34 AM - Run 2
OTL by OldTimer - Version 3.2.42.2 Folder = C:\Documents and Settings\root\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-M-yy

3.00 Gb Total Physical Memory | 1.90 Gb Available Physical Memory | 63.29% Memory free
4.84 Gb Paging File | 3.87 Gb Available in Paging File | 79.99% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.29 Gb Total Space | 7.64 Gb Free Space | 41.76% Space Free | Partition Type: FAT32
Drive D: | 96.71 Gb Total Space | 71.25 Gb Free Space | 73.67% Space Free | Partition Type: FAT32
Drive L: | 465.75 Gb Total Space | 463.25 Gb Free Space | 99.46% Space Free | Partition Type: NTFS
Drive M: | 68.36 Gb Total Space | 35.01 Gb Free Space | 51.21% Space Free | Partition Type: NTFS

Computer Name: TYANS2469 | User Name: root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-05-06 18:49:02 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
PRC - [2012-03-26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2010-06-21 13:52:26 | 000,388,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) -- C:\WINDOWS\system32\LxrSII1s.exe
PRC - [2009-10-24 03:47:58 | 000,409,096 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\WinAVAlarm.exe
PRC - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\3dm2.exe
PRC - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
PRC - [2009-10-16 18:37:22 | 001,325,936 | ---- | M] (Seagate) -- C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
PRC - [2009-03-25 15:32:18 | 000,102,400 | ---- | M] (LSI) -- C:\Program Files\MegaRAID Storage Manager\MegaPopup\popup.exe
PRC - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
PRC - [2009-03-02 11:27:10 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\MegaRAID Storage Manager\JRE\bin\javaw.exe
PRC - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008-04-13 17:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe
PRC - [2007-01-31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2004-12-14 04:44:30 | 000,065,536 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
PRC - [2002-10-15 18:00:20 | 001,818,624 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS\mixer.exe
PRC - [2000-04-05 16:03:10 | 000,388,096 | ---- | M] (Meikel.com) -- C:\Program Files\FreeMem Standard\freemem.exe


========== Modules (No Company Name) ==========

MOD - [2011-11-03 18:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
MOD - [2008-11-17 12:11:04 | 000,138,296 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\CIMPlugin.dll
MOD - [2008-11-17 12:11:00 | 002,034,792 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegcommon.dll
MOD - [2008-11-17 12:11:00 | 000,273,512 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegclient.dll
MOD - [2008-11-17 12:11:00 | 000,146,544 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegslp_client.dll
MOD - [2008-11-17 12:11:00 | 000,089,200 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegexportserver.dll
MOD - [2008-11-17 12:11:00 | 000,068,712 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\peglistener.dll
MOD - [2008-11-17 12:10:58 | 000,138,336 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\storelibirjni.dll
MOD - [2008-11-17 12:10:54 | 000,142,432 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\storelibjni.dll
MOD - [2008-11-17 12:10:52 | 000,068,704 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\Authenticate.dll
MOD - [2008-05-12 19:52:06 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\AlertStrings.dll
MOD - [2008-04-13 17:12:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008-04-13 17:11:52 | 000,498,742 | ---- | M] () -- C:\WINDOWS\system32\dxmasf.dll
MOD - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\UPS\upsman\upsman.exe -- (UPSMan)
SRV - [2012-05-12 00:10:16 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) [Auto | Running] -- C:\WINDOWS\system32\LxrSII1s.exe -- (LxrSII1s)
SRV - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] () [Auto | Running] -- C:\Program Files\AMCC\3DM2/3dm2.exe -- (3DM2)
SRV - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) [Auto | Running] -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (SgtSch2Svc)
SRV - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe -- (MegaMonitorSrv)
SRV - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe -- (MSMFramework)
SRV - [2007-01-31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2003-03-03 13:33:40 | 000,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- c:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\root\LOCALS~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\Mach3.sys -- (Mach3)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix_1\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\root\LOCALS~1\Temp\AMDPCI.sys -- (AMDPCI)
DRV - [2011-04-19 17:06:32 | 000,167,584 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\snapman.sys -- (snapman)
DRV - [2011-04-01 21:30:32 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\timntr.sys -- (timounter)
DRV - [2011-04-01 21:30:32 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2011-04-01 21:30:14 | 000,368,480 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\tdrpman.sys -- (tdrpman)
DRV - [2010-06-02 16:05:02 | 000,109,184 | R--- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\symmpi.sys -- (Symmpi)
DRV - [2009-12-30 10:36:56 | 000,063,448 | ---- | M] (Lexar Media, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LxrSII1d.sys -- (LxrSII1d)
DRV - [2009-06-01 13:36:34 | 000,082,432 | ---- | M] (AMCC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\3wareDrv.sys -- (3wareDrv)
DRV - [2009-05-06 08:59:12 | 004,069,376 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009-02-20 19:09:16 | 000,044,032 | R--- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GigasetGenericUSB.sys -- (GigasetGenericUSB)
DRV - [2008-04-13 11:56:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008-04-13 11:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008-01-02 11:07:06 | 001,404,544 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmudax3.sys -- (cmuda3)
DRV - [2007-07-20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006-11-22 10:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2004-06-29 14:25:26 | 000,007,680 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\dontgo.sys -- (dontgo)
DRV - [2004-06-24 18:37:52 | 000,826,752 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmudau.sys -- (cmudau)
DRV - [2002-11-18 15:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002-09-16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001-08-17 12:49:00 | 000,075,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpae.sys -- (atirage3)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.ebay.com/ [binary data]
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....erify2?&.src=ym
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes\{2A696BCE-44CF-45a4-B905-59CDFA08531A}: "URL" = http://del.icio.us/s...Terms}&type=all
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes\{7B3A7E4E-375E-41FE-B8EC-8D9CCE30AE37}: "URL" = http://search.avg.co...}&ychte=aa&nt=1
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: D:\canon prog\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files\DAP\DAPFireFox [2011-02-17 00:52:34 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2012-05-11 02:57:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {78875F5C-A685-4405-8DC5-D48DC65452B0} - No CLSID value found.
O2 - BHO: (Download Accelerator Plus Integration) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\DAP\dapieloader.dll (SpeedBit Ltd.)
O3 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\Toolbar\WebBrowser: (no name) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - No CLSID value found.
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Popup] C:\Program Files\MegaRAID Storage Manager\MegaPopup\Popup.exe (LSI)
O4 - HKLM..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [WinAVAlarm] C:\Program Files\AMCC\3DM2\WinAVAlarm.exe (LSI)
O4 - HKU\S-1-5-21-839522115-115176313-2147125571-1003..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-839522115-115176313-2147125571-1003..\Run: [FreeMem Pro] C:\Program Files\FreeMem Standard\freemem.exe (Meikel.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O15 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..Trusted Ranges: Range2 ([http] in Trusted sites)
O15 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..Trusted Ranges: Range3 ([http] in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 196.1.69.98 196.1.69.99
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AAC6870A-D985-48FE-9B39-E7D3F8DC8A21}: DhcpNameServer = 196.1.69.98 196.1.69.99
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-06-15 07:41:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012-05-11 14:23:52 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\root\Recent
[2012-05-11 14:20:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012-05-11 14:16:14 | 000,000,000 | ---D | C] -- C:\Program Files\Futuremark
[2012-05-11 14:16:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Futuremark
[2012-05-11 03:20:43 | 000,000,000 | -HSD | C] -- C:\Recycled
[2012-05-11 02:46:52 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012-05-11 02:46:52 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012-05-11 02:46:52 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012-05-11 02:46:52 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012-05-11 02:46:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012-05-11 02:44:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012-05-11 02:03:50 | 000,000,000 | ---D | C] -- C:\_OTL
[2012-05-09 23:11:01 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
[2012-05-04 21:05:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3_files
[2012-04-24 23:50:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-04-23 00:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012-04-23 00:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012-04-23 00:30:06 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012-04-21 19:23:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Application Data\ZoomBrowser EX
[2012-04-21 15:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2012-04-21 15:06:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2012-04-18 23:46:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Local Settings\Application Data\CANON_INC
[2012-04-13 00:18:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC

========== Files - Modified Within 30 Days ==========

[2012-05-12 02:10:02 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-05-12 00:56:36 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job
[2012-05-11 22:55:06 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-05-11 14:21:06 | 000,001,646 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PCMark05.lnk
[2012-05-11 09:22:44 | 000,000,230 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012-05-11 03:07:04 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-05-11 02:57:02 | 000,178,544 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2012-05-11 02:57:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-05-11 02:01:36 | 010,937,936 | ---- | M] () -- C:\Documents and Settings\root\My Documents\eu211w-c-en.pdf
[2012-05-11 02:00:46 | 004,743,968 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Canon_Professional_Product_Guide_new.pdf
[2012-05-11 01:55:58 | 008,391,652 | ---- | M] () -- C:\Documents and Settings\root\Desktop\EOS-1D_X-p8593-c3945-en_EU-1332758131.pdf.dap
[2012-05-09 03:18:48 | 000,101,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012-05-08 17:55:46 | 029,570,446 | ---- | M] () -- C:\Documents and Settings\root\Desktop\eos5dmkiii-im2-c-en.pdf
[2012-05-07 19:40:22 | 000,000,070 | ---- | M] () -- C:\Documents and Settings\root\default.pls
[2012-05-06 18:49:02 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
[2012-05-06 07:52:44 | 000,001,919 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012-05-05 14:05:36 | 010,964,035 | ---- | M] () -- C:\Documents and Settings\root\Desktop\190O0065.JPG
[2012-05-04 21:14:26 | 000,034,919 | ---- | M] () -- C:\Documents and Settings\root\Desktop\print1_cwlke.pdf
[2012-05-04 21:11:26 | 000,026,065 | ---- | M] () -- C:\Documents and Settings\root\Desktop\Snoopy001_18_zacld.pdf
[2012-05-04 21:06:10 | 000,054,725 | ---- | M] () -- C:\Documents and Settings\root\Desktop\powerpuff_girls1_yfjcs.pdf
[2012-05-04 21:05:36 | 000,002,521 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3.htm
[2012-05-02 00:03:44 | 001,556,821 | ---- | M] () -- C:\Documents and Settings\root\My Documents\ecb350.pdf
[2012-05-01 22:26:52 | 002,012,180 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Clik%202011%20Gear%20Set%20Print.pdf
[2012-04-28 03:36:50 | 002,957,829 | ---- | M] () -- C:\Documents and Settings\root\My Documents\EOS-1Ds-MkII-Whitepaper.pdf
[2012-04-21 15:06:36 | 000,000,594 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:14 | 000,000,461 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-21 07:22:26 | 004,515,558 | ---- | M] () -- C:\Documents and Settings\root\My Documents\canon EOS_1Ds_MarkII user guide.pdf
[2012-04-21 07:15:00 | 009,150,824 | ---- | M] () -- C:\Documents and Settings\root\My Documents\Digital Cameras, Canon EOS-1Ds Mark II Digital Camera Test Image.mht
[2012-04-20 16:42:06 | 000,009,830 | ---- | M] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:02 | 000,393,808 | ---- | M] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:12 | 000,000,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-17 07:15:10 | 000,337,174 | ---- | M] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-15 23:17:24 | 000,019,454 | ---- | M] () -- C:\Documents and Settings\root\My Documents\cc_20120415_231710.reg
[2012-04-13 00:31:20 | 001,742,408 | ---- | M] () -- C:\WINDOWS\System32\MRT.exe
[2012-04-12 22:58:38 | 000,000,000 | ---- | M] () -- C:\WINDOWS\vpd.properties

========== Files Created - No Company Name ==========

[2012-05-11 14:21:05 | 000,001,646 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PCMark05.lnk
[2012-05-11 02:48:11 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012-05-11 02:46:52 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012-05-11 02:46:52 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012-05-11 02:46:52 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012-05-11 02:46:52 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012-05-11 02:46:52 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012-05-11 02:01:28 | 010,937,936 | ---- | C] () -- C:\Documents and Settings\root\My Documents\eu211w-c-en.pdf
[2012-05-11 02:00:43 | 004,743,968 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Canon_Professional_Product_Guide_new.pdf
[2012-05-11 01:53:27 | 008,391,652 | ---- | C] () -- C:\Documents and Settings\root\Desktop\EOS-1D_X-p8593-c3945-en_EU-1332758131.pdf.dap
[2012-05-08 17:51:01 | 029,570,446 | ---- | C] () -- C:\Documents and Settings\root\Desktop\eos5dmkiii-im2-c-en.pdf
[2012-05-08 06:39:06 | 010,964,035 | ---- | C] () -- C:\Documents and Settings\root\Desktop\190O0065.JPG
[2012-05-04 21:14:27 | 000,034,919 | ---- | C] () -- C:\Documents and Settings\root\Desktop\print1_cwlke.pdf
[2012-05-04 21:11:28 | 000,026,065 | ---- | C] () -- C:\Documents and Settings\root\Desktop\Snoopy001_18_zacld.pdf
[2012-05-04 21:06:15 | 000,054,725 | ---- | C] () -- C:\Documents and Settings\root\Desktop\powerpuff_girls1_yfjcs.pdf
[2012-05-04 21:05:33 | 000,002,521 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Powerpuff_Girls3.htm
[2012-05-02 00:03:43 | 001,556,821 | ---- | C] () -- C:\Documents and Settings\root\My Documents\ecb350.pdf
[2012-05-01 22:26:51 | 002,012,180 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Clik%202011%20Gear%20Set%20Print.pdf
[2012-04-28 03:36:48 | 002,957,829 | ---- | C] () -- C:\Documents and Settings\root\My Documents\EOS-1Ds-MkII-Whitepaper.pdf
[2012-04-25 00:00:56 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-04-24 23:51:03 | 000,001,919 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012-04-24 23:50:57 | 000,001,651 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-04-21 15:06:34 | 000,000,594 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:12 | 000,000,461 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-21 07:22:25 | 004,515,558 | ---- | C] () -- C:\Documents and Settings\root\My Documents\canon EOS_1Ds_MarkII user guide.pdf
[2012-04-21 07:14:58 | 009,150,824 | ---- | C] () -- C:\Documents and Settings\root\My Documents\Digital Cameras, Canon EOS-1Ds Mark II Digital Camera Test Image.mht
[2012-04-20 16:43:08 | 000,009,830 | ---- | C] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:00 | 000,393,808 | ---- | C] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:11 | 000,000,443 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-17 07:15:04 | 000,337,174 | ---- | C] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-15 23:17:13 | 000,019,454 | ---- | C] () -- C:\Documents and Settings\root\My Documents\cc_20120415_231710.reg
[2012-04-05 00:33:28 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\GkSui16.EXE
[2012-02-16 06:51:36 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011-07-12 09:27:54 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011-06-27 19:30:52 | 000,002,828 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2011-06-26 14:35:48 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\5B3206E10A.sys
[2010-11-11 11:45:58 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\ScsiOat.dll
[2010-10-08 20:16:46 | 000,000,093 | ---- | C] () -- C:\WINDOWS\WFT-E5Utility.INI
[2010-10-03 10:18:19 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010-09-22 05:24:26 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ICOMP.EXE
[2010-09-11 09:41:26 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2010-08-22 23:02:09 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-08-19 16:47:18 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\root\Application Data\$_hpcst$.hpc
[2010-08-18 23:39:52 | 000,000,171 | ---- | C] () -- C:\Documents and Settings\root\Application Data\default.rss
[2010-08-18 23:39:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\root\Application Data\downloads.m3u
[2010-08-17 20:52:06 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\CMRMDRV3.dll
[2010-08-15 07:04:35 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2010-08-15 07:03:21 | 000,479,232 | ---- | C] () -- C:\WINDOWS\System32\Cmeaupci.exe
[2010-08-15 07:03:21 | 000,000,379 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfl
[2010-08-15 07:02:57 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\CmiInstallResAll.dll
[2010-08-15 07:02:57 | 000,003,091 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfg
[2010-08-15 07:02:57 | 000,000,215 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.imi
[2010-08-15 07:02:56 | 000,000,779 | ---- | C] () -- C:\WINDOWS\cmudax3.ini
[2010-08-10 18:37:14 | 000,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2010-07-11 18:20:38 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CmiUSB2Uninstall.exe
[2010-06-30 21:03:01 | 000,000,230 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010-06-27 01:35:33 | 000,002,162 | ---- | C] () -- C:\WINDOWS\Cmudau.ini
[2010-06-27 01:05:53 | 000,000,057 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2010-06-24 23:16:10 | 000,232,840 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.exe
[2010-06-24 23:16:10 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.dll
[2010-06-24 20:51:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010-06-24 15:49:37 | 000,001,150 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2010-06-23 23:58:29 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2010-06-23 22:53:12 | 000,000,112 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2010-06-23 22:53:12 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2010-06-23 22:52:05 | 000,000,246 | ---- | C] () -- C:\WINDOWS\System32\dl.exe
[2010-06-23 07:48:52 | 000,103,936 | ---- | C] () -- C:\Documents and Settings\root\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-06-22 23:06:43 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-06-22 23:06:43 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-06-16 00:27:49 | 001,742,408 | ---- | C] () -- C:\WINDOWS\System32\MRT.exe
[2010-06-15 07:46:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-06-15 07:38:00 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-06-15 07:30:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-06-15 07:29:30 | 000,101,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2010-07-01 23:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010-07-18 19:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gigaset QuickSync
[2010-07-18 20:04:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cached Installations
[2010-08-10 13:02:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2010-09-14 21:12:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grass Valley
[2010-09-14 21:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canopus
[2010-10-16 12:07:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AMCC
[2011-02-08 17:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011-02-17 00:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2011-03-15 08:19:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011-03-17 22:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolarWinds
[2011-04-01 21:30:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2011-10-05 22:49:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ClubSanDisk
[2011-10-23 00:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PassMark
[2012-04-21 15:33:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2010-11-23 06:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\HD Tune Pro
[2011-01-06 21:17:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\Eye-Fi
[2011-01-06 21:28:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\fi.eye.center.E430518E652B889A80EC0E8A6E532C09FF36DF62.1
[2011-07-06 20:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\AVG9
[2012-05-12 00:56:36 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job

========== Purity Check ==========



========== Custom Scans ==========

< >

< MD5 for: IEXPLORE.EXE >
[2010-06-21 13:58:04 | 000,093,008 | ---- | M] (Microsoft Corporation) MD5=8324B0E332BF0AA633143D66F9D848A5 -- C:\WINDOWS\ie8\iexplore.exe
[2010-06-21 13:57:26 | 000,092,992 | ---- | M] (Microsoft Corporation) MD5=948357FA4AB362A4BBDA6852F1FC7886 -- C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2010-06-21 14:00:24 | 000,632,580 | ---- | M] (Microsoft Corporation) MD5=AE9E928A7CC7F2A96AC1C6D981005D19 -- C:\Program Files\Internet Explorer\iexplore.exe
[2010-06-21 13:52:00 | 000,632,580 | ---- | M] (Microsoft Corporation) MD5=AE9E928A7CC7F2A96AC1C6D981005D19 -- C:\WINDOWS\system32\dllcache\iexplore.exe

< MD5 for: REGEDIT.EXE >
[2010-06-21 13:58:36 | 000,146,112 | ---- | M] (Microsoft Corporation) MD5=D52229773D26478F30559440C85D20CD -- C:\WINDOWS\$NtServicePackUninstall$\regedit.exe
[2010-06-21 13:59:10 | 000,146,096 | ---- | M] (Microsoft Corporation) MD5=FC089B1716EDAD0531A1C7926811180C -- C:\WINDOWS\regedit.exe
[2010-06-21 13:57:36 | 000,146,096 | ---- | M] (Microsoft Corporation) MD5=FC089B1716EDAD0531A1C7926811180C -- C:\WINDOWS\ServicePackFiles\i386\regedit.exe

< MD5 for: REGSVR32.EXE >
[2010-06-21 13:58:26 | 000,011,496 | ---- | M] (Microsoft Corporation) MD5=3125AC60F8A1402D1B1B4C1E63906C5E -- C:\WINDOWS\$NtServicePackUninstall$\regsvr32.exe
[2010-07-03 08:49:16 | 000,040,448 | ---- | M] (Microsoft Corporation) MD5=6A6AE401EA3D68AC510555214874BC1D -- C:\WINDOWS\system32\regsvr32.exe
[2010-06-21 13:57:28 | 000,011,480 | ---- | M] (Microsoft Corporation) MD5=7E27AFFE3D313F1743C9DFD923A5F474 -- C:\WINDOWS\ServicePackFiles\i386\regsvr32.exe

< MD5 for: USERINIT.EXE >
[2010-06-21 13:58:22 | 000,024,416 | ---- | M] (Microsoft Corporation) MD5=09E2D2EC83F83B59691DE3CB283C9BBF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2010-06-21 13:57:32 | 000,025,936 | ---- | M] (Microsoft Corporation) MD5=16A1750C90C84815D6B4ABC5B9454B26 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2010-06-21 13:52:30 | 000,025,936 | ---- | M] (Microsoft Corporation) MD5=16A1750C90C84815D6B4ABC5B9454B26 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WSCNTFY.EXE >
[2010-07-11 17:27:12 | 000,013,536 | ---- | M] (Microsoft Corporation) MD5=1432AACDF69334B9305F0E163DF75A11 -- C:\WINDOWS\system32\wscntfy.exe
[2010-06-21 13:57:36 | 000,013,536 | ---- | M] (Microsoft Corporation) MD5=28345CC26F676AA1BD65E82562A3F23C -- C:\WINDOWS\ServicePackFiles\i386\wscntfy.exe
[2010-06-21 13:58:46 | 000,013,552 | ---- | M] (Microsoft Corporation) MD5=A03E215FF5CA42EA806BD48B39270929 -- C:\WINDOWS\$NtServicePackUninstall$\wscntfy.exe

< MD5 for: WUAUCLT.EXE >
[2010-06-21 13:57:28 | 000,110,872 | ---- | M] (Microsoft Corporation) MD5=16A492BFD3E5EFE041151E1D04E17D73 -- C:\WINDOWS\ServicePackFiles\i386\wuauclt.exe
[2010-06-21 13:58:46 | 000,110,888 | ---- | M] (Microsoft Corporation) MD5=5B5A45A52491E009715EE680B1770AB1 -- C:\WINDOWS\$NtServicePackUninstall$\wuauclt.exe
[2010-07-11 17:27:20 | 000,046,924 | ---- | M] (Microsoft Corporation) MD5=ECCCBFFC9B08306C57A535809A05E5CA -- C:\WINDOWS\system32\wuauclt.exe

< >

< End of report >
  • 0

#12
Gammo

Gammo

    Member 2k

  • Malware Removal
  • 2,299 posts
  • Locate your Windows XP installation CD. If you don't have one, you'll need to locate a directory on your system that's named"i386" (without the quotes). This directory may be on a hidden partition on your hard drive.
  • Go to Start, then to Run, and type in "SFC.EXE /SCANNOW" (without the quotes - and with a space between the SFC.EXE and the /SCANNOW). The press Enter.
  • The program may (or it may not) ask you for your Windows XP installation CD - please insert it at the prompt.







Run OTL
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the box that says Scan All Users.
  • Under the Custom Scan box paste this in


    /md5start
    wuauclt.exe
    userinit.exe
    regedit.exe
    wscntfy.exe
    iexplore.exe
    regsvr32.exe
    /md5stop


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time





ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista/Windows 7 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here to run the scan.

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: Posted Image
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: Posted Image
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: Posted Image
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
  • 0

#13
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
I have the original win xp cd. so far I press the retry button more than 100 times. is this normal? still not completed windows file protection
OK ,, after 2 hours just now completed the file protection

Edited by cap10h, 12 May 2012 - 08:05 AM.

  • 0

#14
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
OTL logfile created on: 12-5-12 5:07:01 PM - Run 3
OTL by OldTimer - Version 3.2.42.2 Folder = C:\Documents and Settings\root\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-M-yy

3.00 Gb Total Physical Memory | 1.77 Gb Available Physical Memory | 58.89% Memory free
4.84 Gb Paging File | 3.70 Gb Available in Paging File | 76.46% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 18.29 Gb Total Space | 6.86 Gb Free Space | 37.52% Space Free | Partition Type: FAT32
Drive D: | 96.71 Gb Total Space | 71.25 Gb Free Space | 73.67% Space Free | Partition Type: FAT32
Drive L: | 465.75 Gb Total Space | 463.25 Gb Free Space | 99.46% Space Free | Partition Type: NTFS
Drive M: | 68.36 Gb Total Space | 34.40 Gb Free Space | 50.32% Space Free | Partition Type: NTFS

Computer Name: TYANS2469 | User Name: root | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012-05-06 18:49:02 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
PRC - [2012-03-26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2010-06-21 13:52:26 | 000,388,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
PRC - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) -- C:\WINDOWS\system32\LxrSII1s.exe
PRC - [2009-10-24 03:47:58 | 000,409,096 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\WinAVAlarm.exe
PRC - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] (LSI) -- C:\Program Files\AMCC\3DM2\3dm2.exe
PRC - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
PRC - [2009-10-16 18:37:22 | 001,325,936 | ---- | M] (Seagate) -- C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
PRC - [2009-03-25 15:32:18 | 000,102,400 | ---- | M] (LSI) -- C:\Program Files\MegaRAID Storage Manager\MegaPopup\popup.exe
PRC - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
PRC - [2009-03-02 11:27:10 | 000,144,792 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\MegaRAID Storage Manager\JRE\bin\javaw.exe
PRC - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2008-04-13 17:12:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe
PRC - [2007-01-31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2002-10-15 18:00:20 | 001,818,624 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS\mixer.exe


========== Modules (No Company Name) ==========

MOD - [2011-11-03 18:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2010-09-08 10:46:42 | 003,849,216 | ---- | M] () -- C:\Program Files\ffdshow\ffdshow.ax
MOD - [2010-03-15 11:28:24 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe
MOD - [2008-11-17 12:11:04 | 000,138,296 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\CIMPlugin.dll
MOD - [2008-11-17 12:11:00 | 002,034,792 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegcommon.dll
MOD - [2008-11-17 12:11:00 | 000,273,512 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegclient.dll
MOD - [2008-11-17 12:11:00 | 000,146,544 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegslp_client.dll
MOD - [2008-11-17 12:11:00 | 000,089,200 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\pegexportserver.dll
MOD - [2008-11-17 12:11:00 | 000,068,712 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\peglistener.dll
MOD - [2008-11-17 12:10:58 | 000,138,336 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\storelibirjni.dll
MOD - [2008-11-17 12:10:54 | 000,142,432 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\storelibjni.dll
MOD - [2008-11-17 12:10:52 | 000,068,704 | R--- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\Authenticate.dll
MOD - [2008-05-12 19:52:06 | 000,065,536 | ---- | M] () -- C:\WINDOWS\system32\AlertStrings.dll
MOD - [2008-04-13 17:12:04 | 000,562,176 | ---- | M] () -- C:\WINDOWS\system32\qedit.dll
MOD - [2008-04-13 17:12:00 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008-04-13 17:11:52 | 000,498,742 | ---- | M] () -- C:\WINDOWS\system32\dxmasf.dll
MOD - [2008-04-13 17:11:52 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\UPS\upsman\upsman.exe -- (UPSMan)
SRV - [2012-05-12 00:10:16 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [Auto | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012-03-26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2009-12-30 13:21:02 | 000,065,536 | ---- | M] (Lexar Media, Inc.) [Auto | Running] -- C:\WINDOWS\system32\LxrSII1s.exe -- (LxrSII1s)
SRV - [2009-10-22 08:07:10 | 001,354,248 | ---- | M] () [Auto | Running] -- C:\Program Files\AMCC\3DM2/3dm2.exe -- (3DM2)
SRV - [2009-10-16 18:39:28 | 000,431,456 | ---- | M] (Seagate) [Auto | Running] -- C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (SgtSch2Svc)
SRV - [2009-03-25 13:47:00 | 000,475,136 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\MegaMonitor\mrmonitor.exe -- (MegaMonitorSrv)
SRV - [2008-08-29 15:20:56 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008-04-05 20:43:38 | 000,072,800 | ---- | M] () [Auto | Running] -- C:\Program Files\MegaRAID Storage Manager\Framework\VivaldiFramework.exe -- (MSMFramework)
SRV - [2007-01-31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2003-03-03 13:33:40 | 000,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- c:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\root\LOCALS~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\Mach3.sys -- (Mach3)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix_1\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\root\LOCALS~1\Temp\AMDPCI.sys -- (AMDPCI)
DRV - [2011-04-19 17:06:32 | 000,167,584 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\snapman.sys -- (snapman)
DRV - [2011-04-01 21:30:32 | 000,441,760 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\timntr.sys -- (timounter)
DRV - [2011-04-01 21:30:32 | 000,044,384 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2011-04-01 21:30:14 | 000,368,480 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\tdrpman.sys -- (tdrpman)
DRV - [2010-06-02 16:05:02 | 000,109,184 | R--- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\symmpi.sys -- (Symmpi)
DRV - [2009-12-30 10:36:56 | 000,063,448 | ---- | M] (Lexar Media, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\LxrSII1d.sys -- (LxrSII1d)
DRV - [2009-06-01 13:36:34 | 000,082,432 | ---- | M] (AMCC) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\3wareDrv.sys -- (3wareDrv)
DRV - [2009-02-20 19:09:16 | 000,044,032 | R--- | M] (Siemens Home and Office Communication Devices GmbH & Co. KG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\GigasetGenericUSB.sys -- (GigasetGenericUSB)
DRV - [2008-04-13 11:56:50 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS)
DRV - [2008-04-13 11:45:30 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008-01-02 11:07:06 | 001,404,544 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\cmudax3.sys -- (cmuda3)
DRV - [2007-07-20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006-11-22 10:01:48 | 000,693,760 | ---- | M] (Aladdin Knowledge Systems Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2004-08-03 22:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004-06-29 14:25:26 | 000,007,680 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\dontgo.sys -- (dontgo)
DRV - [2004-06-24 18:37:52 | 000,826,752 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmudau.sys -- (cmudau)
DRV - [2002-11-18 15:51:40 | 000,377,358 | ---- | M] (C-Media Inc) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci) C-Media PCI Audio Driver (WDM)
DRV - [2002-09-16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [2001-08-17 12:49:00 | 000,075,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpae.sys -- (atirage3)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}


IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.ebay.com/ [binary data]
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo....erify2?&.src=ym
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes\{2A696BCE-44CF-45a4-B905-59CDFA08531A}: "URL" = http://del.icio.us/s...Terms}&type=all
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\SearchScopes\{7B3A7E4E-375E-41FE-B8EC-8D9CCE30AE37}: "URL" = http://search.avg.co...}&ychte=aa&nt=1
IE - HKU\S-1-5-21-839522115-115176313-2147125571-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: D:\canon prog\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{F17C1572-C9EC-4e5c-A542-D05CBB5C5A08}: C:\Program Files\DAP\DAPFireFox [2011-02-17 00:52:34 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2012-05-11 02:57:10 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {78875F5C-A685-4405-8DC5-D48DC65452B0} - No CLSID value found.
O2 - BHO: (Download Accelerator Plus Integration) - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\DAP\dapieloader.dll (SpeedBit Ltd.)
O3 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..\Toolbar\WebBrowser: (no name) - {61D1C847-DF80-423A-8C6D-DC03B97E6EBE} - No CLSID value found.
O4 - HKLM..\Run: [C-Media Mixer] C:\WINDOWS\mixer.exe (C-Media Electronic Inc. (www.cmedia.com.tw))
O4 - HKLM..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe (Seagate)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Popup] C:\Program Files\MegaRAID Storage Manager\MegaPopup\Popup.exe (LSI)
O4 - HKLM..\Run: [PRONoMgr.exe] c:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [WinAVAlarm] C:\Program Files\AMCC\3DM2\WinAVAlarm.exe (LSI)
O4 - HKU\S-1-5-21-839522115-115176313-2147125571-1003..\Run: [ccleaner] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-839522115-115176313-2147125571-1003..\Run: [FreeMem Pro] C:\Program Files\FreeMem Standard\freemem.exe (Meikel.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm ()
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm ()
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm ()
O15 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..Trusted Ranges: Range2 ([http] in Trusted sites)
O15 - HKU\S-1-5-21-839522115-115176313-2147125571-1003\..Trusted Ranges: Range3 ([http] in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 196.1.69.98 196.1.69.99
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AAC6870A-D985-48FE-9B39-E7D3F8DC8A21}: DhcpNameServer = 196.1.69.98 196.1.69.99
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-06-15 07:41:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012-05-12 17:01:53 | 000,116,224 | ---- | C] (Xerox) -- C:\WINDOWS\System32\dllcache\xrxwiadr.dll
[2012-05-12 17:01:48 | 000,023,040 | ---- | C] (Xerox Corporation) -- C:\WINDOWS\System32\dllcache\xrxwbtmp.dll
[2012-05-12 17:01:22 | 000,099,865 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\xlog.exe
[2012-05-12 17:01:17 | 000,016,970 | ---- | C] (US Robotics MCD (Megahertz)) -- C:\WINDOWS\System32\dllcache\xem336n5.sys
[2012-05-12 17:00:50 | 000,154,624 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\wlluc48.sys
[2012-05-12 17:00:45 | 000,034,890 | ---- | C] (Raytheon Corp.) -- C:\WINDOWS\System32\dllcache\wlandrv2.sys
[2012-05-12 17:00:31 | 000,771,581 | ---- | C] (Rockwell) -- C:\WINDOWS\System32\dllcache\winacisa.sys
[2012-05-12 17:00:05 | 000,035,871 | ---- | C] (Winbond Electronics Corp.) -- C:\WINDOWS\System32\dllcache\wbfirdma.sys
[2012-05-12 16:59:49 | 000,016,925 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w940nd.sys
[2012-05-12 16:59:44 | 000,019,016 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w926nd.sys
[2012-05-12 16:59:39 | 000,019,528 | ---- | C] (Winbond Electronics Corporation) -- C:\WINDOWS\System32\dllcache\w840nd.sys
[2012-05-12 16:59:31 | 000,064,605 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vvoice.sys
[2012-05-12 16:59:25 | 000,397,502 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\vpctcom.sys
[2012-05-12 16:59:19 | 000,604,253 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\vmodem.sys
[2012-05-12 16:59:14 | 000,249,402 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\vinwm.sys
[2012-05-12 16:58:54 | 000,765,884 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usrti.sys
[2012-05-12 16:58:19 | 000,794,399 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806v.sys
[2012-05-12 16:58:15 | 000,793,598 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1806.sys
[2012-05-12 16:58:10 | 000,794,654 | ---- | C] (U.S. Robotics, Inc.) -- C:\WINDOWS\System32\dllcache\usr1801.sys
[2012-05-12 16:58:05 | 000,032,384 | ---- | C] (KLSI USA, Inc.) -- C:\WINDOWS\System32\dllcache\usb101et.sys
[2012-05-12 16:57:36 | 000,050,688 | ---- | C] (UMAX DATA SYSTEMS INC.) -- C:\WINDOWS\System32\dllcache\umaxscan.dll
[2012-05-12 16:57:17 | 000,211,968 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um54scan.dll
[2012-05-12 16:57:12 | 000,216,064 | ---- | C] (UMAX Data Systems Inc.) -- C:\WINDOWS\System32\dllcache\um34scan.dll
[2012-05-12 16:56:52 | 000,166,784 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxpm.sys
[2012-05-12 16:56:47 | 000,525,568 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridxp.dll
[2012-05-12 16:56:43 | 000,159,232 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkbm.sys
[2012-05-12 16:56:38 | 000,440,576 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tridkb.dll
[2012-05-12 16:56:33 | 000,222,336 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3dm.sys
[2012-05-12 16:56:29 | 000,315,520 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\trid3d.dll
[2012-05-12 16:55:43 | 000,123,995 | ---- | C] (Tiger Jet Network) -- C:\WINDOWS\System32\dllcache\tjisdn.sys
[2012-05-12 16:55:36 | 000,138,528 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiulnt5.sys
[2012-05-12 16:55:31 | 000,081,408 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\tgiul50.dll
[2012-05-12 16:55:29 | 000,149,376 | ---- | C] (M-Systems) -- C:\WINDOWS\System32\dllcache\tffsport.sys
[2012-05-12 16:55:24 | 000,017,129 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdkcd31.sys
[2012-05-12 16:55:19 | 000,037,961 | ---- | C] (TDK Corporation) -- C:\WINDOWS\System32\dllcache\tdk100b.sys
[2012-05-12 16:54:59 | 000,036,640 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\t2r4mini.sys
[2012-05-12 16:54:54 | 000,172,768 | ---- | C] (Number Nine Visual Technology) -- C:\WINDOWS\System32\dllcache\t2r4disp.dll
[2012-05-12 16:53:55 | 000,155,648 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnprop.dll
[2012-05-12 16:53:50 | 000,053,248 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlncoin.dll
[2012-05-12 16:53:46 | 000,285,760 | ---- | C] (Stallion Technologies) -- C:\WINDOWS\System32\dllcache\stlnata.sys
[2012-05-12 16:53:40 | 000,016,896 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\stcusb.sys
[2012-05-12 16:53:34 | 000,048,736 | ---- | C] (3Com) -- C:\WINDOWS\System32\dllcache\srwlnd5.sys
[2012-05-12 16:53:06 | 000,019,072 | ---- | C] (Adaptec, Inc.) -- C:\WINDOWS\System32\dllcache\sparrow.sys
[2012-05-12 16:52:17 | 000,058,368 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smiminib.sys
[2012-05-12 16:52:12 | 000,147,200 | ---- | C] (Silicon Motion Inc.) -- C:\WINDOWS\System32\dllcache\smidispb.dll
[2012-05-12 16:52:08 | 000,025,034 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smcpwr2n.sys
[2012-05-12 16:52:03 | 000,035,913 | ---- | C] (SMC) -- C:\WINDOWS\System32\dllcache\smcirda.sys
[2012-05-12 16:51:59 | 000,024,576 | ---- | C] (SMC Networks, Inc.) -- C:\WINDOWS\System32\dllcache\smc8000n.sys
[2012-05-12 16:51:22 | 000,063,547 | ---- | C] (Symbol Technologies) -- C:\WINDOWS\System32\dllcache\sla30nd5.sys
[2012-05-12 16:51:18 | 000,091,294 | ---- | C] (SysKonnect, a business unit of Schneider & Koch & Co. Datensysteme GmbH.) -- C:\WINDOWS\System32\dllcache\skfpwin.sys
[2012-05-12 16:51:13 | 000,094,698 | ---- | C] (SysKonnect GmbH.) -- C:\WINDOWS\System32\dllcache\sk98xwin.sys
[2012-05-12 16:51:03 | 000,032,768 | ---- | C] (SiS Corporation) -- C:\WINDOWS\System32\dllcache\sisnic.sys
[2012-05-12 16:50:25 | 000,161,568 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmusb.sys
[2012-05-12 16:50:21 | 000,018,400 | ---- | C] (Micro Systemation) -- C:\WINDOWS\System32\dllcache\sgsmld.sys
[2012-05-12 16:50:17 | 000,098,080 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiulnt5.sys
[2012-05-12 16:50:13 | 000,386,560 | ---- | C] (Trident Microsystems Inc.) -- C:\WINDOWS\System32\dllcache\sgiul50.dll
[2012-05-12 16:47:22 | 000,017,280 | ---- | C] (SCM Microsystems) -- C:\WINDOWS\System32\dllcache\scr111.sys
[2012-05-12 16:47:13 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmusbm.sys
[2012-05-12 16:47:08 | 000,023,936 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\sccmn50m.sys
[2012-05-12 16:46:47 | 000,077,824 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4m.sys
[2012-05-12 16:46:43 | 000,198,400 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav4.dll
[2012-05-12 16:46:38 | 000,061,504 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3dm.sys
[2012-05-12 16:46:34 | 000,179,264 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3sav3d.dll
[2012-05-12 16:46:30 | 000,210,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mvirge.dll
[2012-05-12 16:46:26 | 000,062,496 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mtrio.dll
[2012-05-12 16:46:22 | 000,041,216 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.sys
[2012-05-12 16:46:17 | 000,182,272 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3mt3d.dll
[2012-05-12 16:46:13 | 000,166,720 | ---- | C] (S3 Incorporated) -- C:\WINDOWS\System32\dllcache\s3m.sys
[2012-05-12 16:46:04 | 000,082,432 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia450.dll
[2012-05-12 16:45:59 | 000,079,872 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rwia430.dll
[2012-05-12 16:45:57 | 000,029,696 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw450ext.dll
[2012-05-12 16:45:56 | 000,027,648 | ---- | C] (Ricoh Co., Ltd.) -- C:\WINDOWS\System32\dllcache\rw430ext.dll
[2012-05-12 16:45:34 | 000,009,216 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\rsmgrstr.dll
[2012-05-12 16:45:25 | 000,079,104 | ---- | C] (Comtrol Corporation) -- C:\WINDOWS\System32\dllcache\rocket.sys
[2012-05-12 16:45:20 | 000,037,563 | ---- | C] (RadioLAN) -- C:\WINDOWS\System32\dllcache\rlnet5.sys
[2012-05-12 16:45:15 | 000,086,097 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\reslog32.dll
[2012-05-12 16:44:50 | 000,714,762 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdmkxx.sys
[2012-05-12 16:44:46 | 000,899,146 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\r2mdkxga.sys
[2012-05-12 16:44:06 | 000,130,942 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlv.sys
[2012-05-12 16:44:02 | 000,112,574 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserlp.sys
[2012-05-12 16:43:58 | 000,128,286 | ---- | C] (PCTEL, INC.) -- C:\WINDOWS\System32\dllcache\ptserli.sys
[2012-05-12 16:43:42 | 000,016,128 | ---- | C] (SCM Microsystems, Inc.) -- C:\WINDOWS\System32\dllcache\pscr.sys
[2012-05-12 16:42:33 | 000,086,016 | ---- | C] (PCtel, Inc.) -- C:\WINDOWS\System32\dllcache\pctspk.exe
[2012-05-12 16:42:17 | 000,026,153 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pcmlm56.sys
[2012-05-12 16:42:16 | 000,029,502 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\pca200e.sys
[2012-05-12 16:42:12 | 000,030,495 | ---- | C] (Linksys) -- C:\WINDOWS\System32\dllcache\pc100nds.sys
[2012-05-12 16:41:18 | 000,054,186 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otcsercb.sys
[2012-05-12 16:41:14 | 000,043,689 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otceth5.sys
[2012-05-12 16:41:10 | 000,027,209 | ---- | C] (Ositech Communications, Inc.) -- C:\WINDOWS\System32\dllcache\otc06x5.sys
[2012-05-12 16:41:04 | 000,054,528 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\opl3sax.sys
[2012-05-12 16:40:40 | 000,051,552 | ---- | C] (Kensington Technology Group) -- C:\WINDOWS\System32\dllcache\ntgrip.sys
[2012-05-12 16:38:43 | 000,087,040 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm6wdm.sys
[2012-05-12 16:38:39 | 000,126,080 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\nm5a2wdm.sys
[2012-05-12 16:38:33 | 000,132,695 | ---- | C] (802.11b) -- C:\WINDOWS\System32\dllcache\netwlan5.sys
[2012-05-12 16:38:20 | 000,039,264 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.sys
[2012-05-12 16:38:17 | 000,060,480 | ---- | C] (NeoMagic Corporation) -- C:\WINDOWS\System32\dllcache\neo20xx.dll
[2012-05-12 16:38:04 | 000,091,488 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3disp.dll
[2012-05-12 16:38:00 | 000,027,936 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i3d.sys
[2012-05-12 16:37:56 | 000,033,088 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.sys
[2012-05-12 16:37:53 | 000,059,104 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128v2.dll
[2012-05-12 16:37:49 | 000,013,664 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.sys
[2012-05-12 16:37:45 | 000,035,392 | ---- | C] (Number Nine Visual Technology Corp.) -- C:\WINDOWS\System32\dllcache\n9i128.dll
[2012-05-12 16:37:34 | 000,075,520 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxport.sys
[2012-05-12 16:37:30 | 000,007,168 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxport.dll
[2012-05-12 16:37:26 | 000,019,968 | ---- | C] (Macronix International Co., Ltd. ) -- C:\WINDOWS\System32\dllcache\mxnic.sys
[2012-05-12 16:37:22 | 000,019,968 | ---- | C] (Moxa Technologies Co., Ltd) -- C:\WINDOWS\System32\dllcache\mxicfg.dll
[2012-05-12 16:37:19 | 000,021,888 | ---- | C] (Moxa Technologies Co., Ltd.) -- C:\WINDOWS\System32\dllcache\mxcard.sys
[2012-05-12 16:36:29 | 000,017,280 | ---- | C] (American Megatrends Inc.) -- C:\WINDOWS\System32\dllcache\mraid35x.sys
[2012-05-12 16:35:35 | 000,164,586 | ---- | C] (Madge Networks Ltd) -- C:\WINDOWS\System32\dllcache\mdgndis5.sys
[2012-05-12 14:08:54 | 000,797,500 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltsmt.sys
[2012-05-12 14:08:50 | 000,802,683 | ---- | C] (Lucent Technologies) -- C:\WINDOWS\System32\dllcache\ltsm.sys
[2012-05-12 14:08:49 | 000,420,992 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntt.sys
[2012-05-12 14:08:46 | 000,576,746 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmntl.sys
[2012-05-12 14:08:45 | 000,606,684 | ---- | C] (LT) -- C:\WINDOWS\System32\dllcache\ltmdmnt.sys
[2012-05-12 14:08:42 | 000,727,786 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ltck000c.sys
[2012-05-12 14:08:28 | 000,070,730 | ---- | C] (Linksys Group, Inc.) -- C:\WINDOWS\System32\dllcache\lne100tx.sys
[2012-05-12 14:08:24 | 000,020,573 | ---- | C] (The Linksts Group ) -- C:\WINDOWS\System32\dllcache\lne100.sys
[2012-05-12 14:08:21 | 000,025,065 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\lmndis3.sys
[2012-05-12 14:08:17 | 000,015,744 | ---- | C] (Litronic Industries) -- C:\WINDOWS\System32\dllcache\lit220p.sys
[2012-05-12 14:08:12 | 000,026,442 | ---- | C] (SMSC) -- C:\WINDOWS\System32\dllcache\lanepic5.sys
[2012-05-12 14:08:08 | 000,019,016 | ---- | C] (Kingston Technology Company ) -- C:\WINDOWS\System32\dllcache\ktc111.sys
[2012-05-12 14:07:20 | 000,023,552 | ---- | C] (MKNet Corporation) -- C:\WINDOWS\System32\dllcache\irmk7.sys
[2012-05-12 14:06:28 | 000,372,824 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\iconf32.dll
[2012-05-12 14:04:11 | 000,068,608 | ---- | C] (Avisioin) -- C:\WINDOWS\System32\dllcache\hpgt53tk.dll
[2012-05-12 14:03:59 | 000,126,976 | ---- | C] (Hewlett Packard) -- C:\WINDOWS\System32\dllcache\hpgt34tk.dll
[2012-05-12 14:03:25 | 000,028,288 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grserial.sys
[2012-05-12 14:03:21 | 000,082,304 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\grclass.sys
[2012-05-12 14:03:17 | 000,017,408 | ---- | C] (Gemplus) -- C:\WINDOWS\System32\dllcache\gpr400.sys
[2012-05-12 14:03:01 | 000,454,912 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fxusbase.sys
[2012-05-12 14:02:48 | 000,455,296 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fusbbase.sys
[2012-05-12 14:02:45 | 000,455,680 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fus2base.sys
[2012-05-12 14:02:38 | 000,442,240 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpnpbase.sys
[2012-05-12 14:02:35 | 000,441,728 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcmbase.sys
[2012-05-12 14:02:32 | 000,444,416 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\fpcibase.sys
[2012-05-12 14:02:31 | 000,034,173 | ---- | C] (Marconi Communications, Inc.) -- C:\WINDOWS\System32\dllcache\forehe.sys
[2012-05-12 14:02:04 | 000,024,618 | ---- | C] (NETGEAR) -- C:\WINDOWS\System32\dllcache\fa410nd5.sys
[2012-05-12 14:01:58 | 000,011,850 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xj.sys
[2012-05-12 14:01:55 | 000,012,362 | ---- | C] (FUJITSU LIMITED) -- C:\WINDOWS\System32\dllcache\f3ab18xi.sys
[2012-05-12 13:59:47 | 000,334,208 | ---- | C] (Yamaha Corp.) -- C:\WINDOWS\System32\dllcache\ds1wdm.sys
[2012-05-12 13:59:38 | 000,028,062 | ---- | C] (National Semiconductor Coproration) -- C:\WINDOWS\System32\dllcache\dp83820.sys
[2012-05-12 13:59:25 | 000,029,696 | ---- | C] (CNet Technology, Inc. ) -- C:\WINDOWS\System32\dllcache\dm9pci5.sys
[2012-05-12 13:59:13 | 000,026,698 | ---- | C] (D-Link Corporation) -- C:\WINDOWS\System32\dllcache\dlh5xnd5.sys
[2012-05-12 13:59:10 | 000,952,007 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diwan.sys
[2012-05-12 13:59:01 | 000,236,060 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\ditrace.exe
[2012-05-12 13:58:59 | 000,038,985 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvsu.dll
[2012-05-12 13:58:55 | 000,031,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvpp.dll
[2012-05-12 13:58:53 | 000,006,729 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\disrvci.dll
[2012-05-12 13:58:47 | 000,091,305 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\dimaint.sys
[2012-05-12 13:58:13 | 000,024,649 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650d.sys
[2012-05-12 13:58:11 | 000,024,648 | ---- | C] (D-Link) -- C:\WINDOWS\System32\dllcache\dfe650.sys
[2012-05-12 13:58:05 | 000,020,928 | ---- | C] (Digital Networks, LLC) -- C:\WINDOWS\System32\dllcache\defpa.sys
[2012-05-12 13:57:29 | 000,048,640 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwrwdm.sys
[2012-05-12 13:57:28 | 000,093,952 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcwdm.sys
[2012-05-12 13:57:26 | 000,111,872 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcspud.sys
[2012-05-12 13:57:24 | 000,003,584 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwcosnt5.sys
[2012-05-12 13:57:22 | 000,072,832 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbwdm.sys
[2012-05-12 13:57:21 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbmidi.sys
[2012-05-12 13:57:19 | 000,003,072 | ---- | C] (Crystal Semiconductor Corp.) -- C:\WINDOWS\System32\dllcache\cwbase.sys
[2012-05-12 13:57:16 | 000,249,856 | ---- | C] (Comtrol® Corporation) -- C:\WINDOWS\System32\dllcache\ctmasetp.dll
[2012-05-12 13:57:04 | 000,216,064 | ---- | C] (COMPAQ Inc.) -- C:\WINDOWS\System32\dllcache\cpscan.dll
[2012-05-12 13:56:37 | 000,020,736 | ---- | C] (OMNIKEY AG) -- C:\WINDOWS\System32\dllcache\cmbp0wdm.sys
[2012-05-12 13:56:21 | 000,980,034 | ---- | C] (Xircom) -- C:\WINDOWS\System32\dllcache\cicap.sys
[2012-05-12 13:56:07 | 000,049,182 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem56n5.sys
[2012-05-12 13:56:06 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem33n5.sys
[2012-05-12 13:56:04 | 000,022,044 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cem28n5.sys
[2012-05-12 13:56:03 | 000,027,164 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce3n5.sys
[2012-05-12 13:56:02 | 000,021,530 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\ce2n5.sys
[2012-05-12 13:55:59 | 000,714,698 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cbmdmkxx.sys
[2012-05-12 13:55:58 | 000,046,108 | ---- | C] (Xircom, Inc.) -- C:\WINDOWS\System32\dllcache\cben5.sys
[2012-05-12 13:55:56 | 000,039,680 | ---- | C] (Silicom Ltd.) -- C:\WINDOWS\System32\dllcache\cb325.sys
[2012-05-12 13:55:54 | 000,037,916 | ---- | C] (Fast Ethernet Controller Provider) -- C:\WINDOWS\System32\dllcache\cb102.sys
[2012-05-12 13:55:53 | 000,032,256 | ---- | C] (Eicon Technology Corporation) -- C:\WINDOWS\System32\dllcache\diapi2NT.dll
[2012-05-12 13:55:51 | 000,164,923 | ---- | C] (Eicon Technology) -- C:\WINDOWS\System32\dllcache\diapi2.sys
[2012-05-12 13:54:53 | 000,031,529 | ---- | C] (BreezeCOM) -- C:\WINDOWS\System32\dllcache\brzwlan.sys
[2012-05-12 13:54:52 | 000,010,368 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbscn.sys
[2012-05-12 13:54:51 | 000,011,008 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brusbmdm.sys
[2012-05-12 13:54:49 | 000,060,416 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brserwdm.sys
[2012-05-12 13:54:48 | 000,009,728 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brserif.dll
[2012-05-12 13:54:47 | 000,005,120 | ---- | C] (Brother Industries,Ltd.) -- C:\WINDOWS\System32\dllcache\brscnrsm.dll
[2012-05-12 13:54:46 | 000,039,552 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparwdm.sys
[2012-05-12 13:54:44 | 000,003,168 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brparimg.sys
[2012-05-12 13:54:42 | 000,041,472 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfusb.dll
[2012-05-12 13:54:41 | 000,032,256 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfrsmg.exe
[2012-05-12 13:54:40 | 000,029,696 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmflpt.dll
[2012-05-12 13:54:38 | 000,015,360 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brmfbidi.dll
[2012-05-12 13:54:37 | 000,003,968 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltup.sys
[2012-05-12 13:54:35 | 000,012,160 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brfiltlo.sys
[2012-05-12 13:54:34 | 000,002,944 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brfilt.sys
[2012-05-12 13:54:33 | 000,012,800 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brevif.dll
[2012-05-12 13:54:32 | 000,009,728 | ---- | C] (Brother Industries Ltd.) -- C:\WINDOWS\System32\dllcache\brcoinst.dll
[2012-05-12 13:54:30 | 000,019,456 | ---- | C] (Brother Industries, Ltd.) -- C:\WINDOWS\System32\dllcache\brbidiif.dll
[2012-05-12 13:54:22 | 000,871,388 | ---- | C] (BCM) -- C:\WINDOWS\System32\dllcache\bcmdm.sys
[2012-05-12 13:54:15 | 000,036,128 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.sys
[2012-05-12 13:54:14 | 000,342,336 | ---- | C] (3Dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\banshee.dll
[2012-05-12 13:54:12 | 000,089,952 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\b1cbase.sys
[2012-05-12 13:54:11 | 000,036,992 | ---- | C] (Aztech Systems Ltd) -- C:\WINDOWS\System32\dllcache\aztw2320.sys
[2012-05-12 13:54:10 | 000,037,568 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmwan.sys
[2012-05-12 13:54:09 | 000,144,384 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmenum.dll
[2012-05-12 13:54:08 | 000,087,552 | ---- | C] (AVM GmbH) -- C:\WINDOWS\System32\dllcache\avmcoxp.dll
[2012-05-12 13:53:29 | 000,097,354 | ---- | C] (Bay Networks, Inc.) -- C:\WINDOWS\System32\dllcache\aspndis3.sys
[2012-05-12 13:53:10 | 000,016,969 | ---- | C] (AmbiCom, Inc.) -- C:\WINDOWS\System32\dllcache\amb8002.sys
[2012-05-12 13:52:51 | 000,046,112 | ---- | C] (Adaptec, Inc ) -- C:\WINDOWS\System32\dllcache\adptsf50.sys
[2012-05-12 13:52:50 | 000,010,880 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\admjoy.sys
[2012-05-12 13:52:48 | 000,747,392 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8830.sys
[2012-05-12 13:52:48 | 000,553,984 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8820.sys
[2012-05-12 13:52:47 | 000,584,448 | ---- | C] (Aureal, Inc.) -- C:\WINDOWS\System32\dllcache\adm8810.sys
[2012-05-12 13:52:43 | 000,061,440 | ---- | C] (Color Flatbed Scanner) -- C:\WINDOWS\System32\dllcache\acerscad.dll
[2012-05-12 13:52:38 | 000,462,848 | ---- | C] (Aureal Inc.) -- C:\WINDOWS\System32\dllcache\a3dapi.dll
[2012-05-12 13:52:35 | 000,148,352 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvsm.sys
[2012-05-12 13:52:34 | 000,762,780 | ---- | C] (3Com, Inc.) -- C:\WINDOWS\System32\dllcache\3cwmcru.sys
[2012-05-12 13:52:34 | 000,689,216 | ---- | C] (3dfx Interactive, Inc.) -- C:\WINDOWS\System32\dllcache\3dfxvs.dll
[2012-05-11 14:23:52 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\root\Recent
[2012-05-11 14:20:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2012-05-11 14:16:14 | 000,000,000 | ---D | C] -- C:\Program Files\Futuremark
[2012-05-11 14:16:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Futuremark
[2012-05-11 03:20:43 | 000,000,000 | -HSD | C] -- C:\Recycled
[2012-05-11 02:46:52 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012-05-11 02:46:52 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012-05-11 02:46:52 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012-05-11 02:46:52 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012-05-11 02:46:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012-05-11 02:44:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012-05-11 02:03:50 | 000,000,000 | ---D | C] -- C:\_OTL
[2012-05-09 23:11:01 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
[2012-04-24 23:50:39 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012-04-23 00:30:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012-04-23 00:30:28 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012-04-23 00:30:06 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012-04-21 19:23:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Application Data\ZoomBrowser EX
[2012-04-21 15:33:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2012-04-21 15:06:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
[2012-04-18 23:46:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\root\Local Settings\Application Data\CANON_INC
[2012-04-13 00:18:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[256 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[118 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-05-12 17:10:02 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-05-12 13:36:12 | 000,000,230 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012-05-12 13:34:44 | 000,000,098 | ---- | M] () -- C:\Documents and Settings\root\default.pls
[2012-05-12 00:56:36 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job
[2012-05-11 22:55:06 | 000,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012-05-11 14:21:06 | 000,001,646 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\PCMark05.lnk
[2012-05-11 03:07:04 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-05-11 02:57:02 | 000,178,544 | ---- | M] () -- C:\WINDOWS\System32\ativvaxx.cap
[2012-05-11 02:57:02 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012-05-11 01:55:58 | 008,391,652 | ---- | M] () -- C:\Documents and Settings\root\Desktop\EOS-1D_X-p8593-c3945-en_EU-1332758131.pdf.dap
[2012-05-09 03:18:48 | 000,101,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012-05-08 17:55:46 | 029,570,446 | ---- | M] () -- C:\Documents and Settings\root\Desktop\eos5dmkiii-im2-c-en.pdf
[2012-05-06 18:49:02 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\root\Desktop\OTL.exe
[2012-05-06 07:52:44 | 000,001,919 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2012-04-21 15:06:36 | 000,000,594 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:14 | 000,000,461 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-20 16:42:06 | 000,009,830 | ---- | M] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:02 | 000,393,808 | ---- | M] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:12 | 000,000,443 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-17 07:15:10 | 000,337,174 | ---- | M] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-13 00:31:20 | 001,742,408 | ---- | M] () -- C:\WINDOWS\System32\MRT.exe
[2012-04-12 22:58:38 | 000,000,000 | ---- | M] () -- C:\WINDOWS\vpd.properties
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[256 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[118 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-05-12 17:01:47 | 000,018,944 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxscnui.dll
[2012-05-12 17:01:42 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\dllcache\xrxftplt.exe
[2012-05-12 16:43:51 | 000,033,280 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisrndr.ax
[2012-05-12 16:43:46 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisdecd.dll
[2012-05-12 16:36:37 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2012-05-12 14:04:08 | 000,165,888 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt53.dll
[2012-05-12 14:04:02 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt42.dll
[2012-05-12 14:03:56 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt34.dll
[2012-05-12 14:03:50 | 000,089,088 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt33.dll
[2012-05-12 14:03:44 | 000,083,968 | ---- | C] () -- C:\WINDOWS\System32\dllcache\hpgt21.dll
[2012-05-12 13:59:08 | 000,029,768 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divasu.dll
[2012-05-12 13:59:05 | 000,037,962 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaprop.dll
[2012-05-12 13:59:03 | 000,006,216 | ---- | C] () -- C:\WINDOWS\System32\dllcache\divaci.dll
[2012-05-12 13:53:58 | 000,023,552 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atixbar.sys
[2012-05-12 13:53:57 | 000,026,624 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativxbar.sys
[2012-05-12 13:53:55 | 000,019,456 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativttxx.sys
[2012-05-12 13:53:54 | 000,009,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\ativmdcd.sys
[2012-05-12 13:53:53 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitvsnd.sys
[2012-05-12 13:53:52 | 000,017,152 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atitunep.sys
[2012-05-12 13:53:51 | 000,026,880 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtsnd.sys
[2012-05-12 13:53:50 | 000,049,920 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atirtcap.sys
[2012-05-12 13:53:47 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atipcxxx.sys
[2012-05-12 13:53:40 | 000,046,464 | ---- | C] () -- C:\WINDOWS\System32\dllcache\atibt829.sys
[2012-05-11 14:21:05 | 000,001,646 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\PCMark05.lnk
[2012-05-11 02:48:11 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012-05-11 02:46:52 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012-05-11 02:46:52 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012-05-11 02:46:52 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012-05-11 02:46:52 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012-05-11 02:46:52 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012-05-11 01:53:27 | 008,391,652 | ---- | C] () -- C:\Documents and Settings\root\Desktop\EOS-1D_X-p8593-c3945-en_EU-1332758131.pdf.dap
[2012-05-08 17:51:01 | 029,570,446 | ---- | C] () -- C:\Documents and Settings\root\Desktop\eos5dmkiii-im2-c-en.pdf
[2012-04-25 00:00:56 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012-04-24 23:51:03 | 000,001,919 | ---- | C] () -- C:\WINDOWS\epplauncher.mif
[2012-04-24 23:50:57 | 000,001,651 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012-04-21 15:06:34 | 000,000,594 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\ZoomBrowser EX.lnk
[2012-04-21 15:06:12 | 000,000,461 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Picture Style Editor.lnk
[2012-04-20 16:43:08 | 000,009,830 | ---- | C] () -- C:\Documents and Settings\root\Desktop\exefix_1.reg
[2012-04-18 23:43:00 | 000,393,808 | ---- | C] () -- C:\Documents and Settings\root\Desktop\pattern.jpg
[2012-04-18 23:40:11 | 000,000,443 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\EOS Utility.lnk
[2012-04-17 07:15:04 | 000,337,174 | ---- | C] () -- C:\Documents and Settings\root\My Documents\bookmark 2012-4-17 s2469.htm
[2012-04-05 00:33:28 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\GkSui16.EXE
[2012-02-16 06:51:36 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011-07-12 09:27:54 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2011-06-27 19:30:52 | 000,002,828 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2011-06-26 14:35:48 | 000,000,056 | RHS- | C] () -- C:\WINDOWS\System32\5B3206E10A.sys
[2010-11-11 11:45:58 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\ScsiOat.dll
[2010-10-08 20:16:46 | 000,000,093 | ---- | C] () -- C:\WINDOWS\WFT-E5Utility.INI
[2010-10-03 10:18:19 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010-09-22 05:24:26 | 000,123,392 | ---- | C] () -- C:\WINDOWS\System32\ICOMP.EXE
[2010-09-11 09:41:26 | 000,000,151 | ---- | C] () -- C:\WINDOWS\PhotoSnapViewer.INI
[2010-08-22 23:02:09 | 000,064,200 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-08-19 16:47:18 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\root\Application Data\$_hpcst$.hpc
[2010-08-18 23:39:52 | 000,000,171 | ---- | C] () -- C:\Documents and Settings\root\Application Data\default.rss
[2010-08-18 23:39:52 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\root\Application Data\downloads.m3u
[2010-08-17 20:52:06 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\CMRMDRV3.dll
[2010-08-15 07:04:35 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2010-08-15 07:03:21 | 000,479,232 | ---- | C] () -- C:\WINDOWS\System32\Cmeaupci.exe
[2010-08-15 07:03:21 | 000,000,379 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfl
[2010-08-15 07:02:57 | 000,241,664 | ---- | C] () -- C:\WINDOWS\System32\CmiInstallResAll.dll
[2010-08-15 07:02:57 | 000,003,091 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.cfg
[2010-08-15 07:02:57 | 000,000,215 | ---- | C] () -- C:\WINDOWS\Cmicnfg3.ini.imi
[2010-08-15 07:02:56 | 000,000,779 | ---- | C] () -- C:\WINDOWS\cmudax3.ini
[2010-08-10 18:37:14 | 000,000,039 | ---- | C] () -- C:\WINDOWS\Irremote.ini
[2010-07-11 18:20:38 | 000,028,672 | ---- | C] () -- C:\WINDOWS\CmiUSB2Uninstall.exe
[2010-06-30 21:03:01 | 000,000,230 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010-06-27 01:35:33 | 000,002,162 | ---- | C] () -- C:\WINDOWS\Cmudau.ini
[2010-06-27 01:05:53 | 000,000,057 | ---- | C] () -- C:\WINDOWS\iexplore.ini
[2010-06-24 23:16:10 | 000,232,840 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.exe
[2010-06-24 23:16:10 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\cmdrvrmu.dll
[2010-06-24 20:51:31 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010-06-24 15:49:37 | 000,001,150 | ---- | C] () -- C:\WINDOWS\ATICIM.INI
[2010-06-23 23:58:29 | 000,000,025 | ---- | C] () -- C:\WINDOWS\mixerdef.ini
[2010-06-23 22:53:12 | 000,000,112 | ---- | C] () -- C:\WINDOWS\CMISETUP.INI
[2010-06-23 22:53:12 | 000,000,026 | ---- | C] () -- C:\WINDOWS\CMCDPLAY.INI
[2010-06-23 22:52:05 | 000,000,246 | ---- | C] () -- C:\WINDOWS\System32\dl.exe
[2010-06-23 07:48:52 | 000,103,936 | ---- | C] () -- C:\Documents and Settings\root\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-06-22 23:06:43 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2010-06-22 23:06:43 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2010-06-16 00:27:49 | 001,742,408 | ---- | C] () -- C:\WINDOWS\System32\MRT.exe
[2010-06-15 07:46:36 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-06-15 07:38:00 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-06-15 07:30:34 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-06-15 07:29:30 | 000,101,440 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== LOP Check ==========

[2010-07-01 23:32:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2010-07-18 19:49:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gigaset QuickSync
[2010-07-18 20:04:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cached Installations
[2010-08-10 13:02:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2010-09-14 21:12:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grass Valley
[2010-09-14 21:31:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canopus
[2010-10-16 12:07:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AMCC
[2011-02-08 17:20:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\boost_interprocess
[2011-02-17 00:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedBit
[2011-03-15 08:19:54 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011-03-17 22:43:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SolarWinds
[2011-04-01 21:30:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2011-10-05 22:49:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ClubSanDisk
[2011-10-23 00:57:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PassMark
[2012-04-21 15:33:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoStitch
[2010-11-23 06:32:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\HD Tune Pro
[2011-01-06 21:17:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\Eye-Fi
[2011-01-06 21:28:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\fi.eye.center.E430518E652B889A80EC0E8A6E532C09FF36DF62.1
[2011-07-06 20:59:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\root\Application Data\AVG9
[2012-05-12 00:56:36 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{8026D239-1350-4C1B-8AE9-20B85C68D34B}.job

========== Purity Check ==========



========== Custom Scans ==========

< MD5 for: IEXPLORE.EXE >
[2010-06-21 13:58:04 | 000,093,008 | ---- | M] (Microsoft Corporation) MD5=8324B0E332BF0AA633143D66F9D848A5 -- C:\WINDOWS\ie8\iexplore.exe
[2010-06-21 13:57:26 | 000,092,992 | ---- | M] (Microsoft Corporation) MD5=948357FA4AB362A4BBDA6852F1FC7886 -- C:\WINDOWS\ServicePackFiles\i386\iexplore.exe
[2010-06-21 14:00:24 | 000,632,580 | ---- | M] (Microsoft Corporation) MD5=AE9E928A7CC7F2A96AC1C6D981005D19 -- C:\Program Files\Internet Explorer\iexplore.exe

< MD5 for: REGEDIT.EXE >
[2010-06-21 13:58:36 | 000,146,112 | ---- | M] (Microsoft Corporation) MD5=D52229773D26478F30559440C85D20CD -- C:\WINDOWS\$NtServicePackUninstall$\regedit.exe
[2010-06-21 13:59:10 | 000,146,096 | ---- | M] (Microsoft Corporation) MD5=FC089B1716EDAD0531A1C7926811180C -- C:\WINDOWS\LastGood\regedit.exe
[2010-06-21 13:59:10 | 000,146,096 | ---- | M] (Microsoft Corporation) MD5=FC089B1716EDAD0531A1C7926811180C -- C:\WINDOWS\regedit.exe
[2010-06-21 13:57:36 | 000,146,096 | ---- | M] (Microsoft Corporation) MD5=FC089B1716EDAD0531A1C7926811180C -- C:\WINDOWS\ServicePackFiles\i386\regedit.exe

< MD5 for: REGSVR32.EXE >
[2010-06-21 13:58:26 | 000,011,496 | ---- | M] (Microsoft Corporation) MD5=3125AC60F8A1402D1B1B4C1E63906C5E -- C:\WINDOWS\$NtServicePackUninstall$\regsvr32.exe
[2010-07-03 08:49:16 | 000,040,448 | ---- | M] (Microsoft Corporation) MD5=6A6AE401EA3D68AC510555214874BC1D -- C:\WINDOWS\LastGood\system32\regsvr32.exe
[2010-07-03 08:49:16 | 000,040,448 | ---- | M] (Microsoft Corporation) MD5=6A6AE401EA3D68AC510555214874BC1D -- C:\WINDOWS\system32\regsvr32.exe
[2010-06-21 13:57:28 | 000,011,480 | ---- | M] (Microsoft Corporation) MD5=7E27AFFE3D313F1743C9DFD923A5F474 -- C:\WINDOWS\ServicePackFiles\i386\regsvr32.exe

< MD5 for: USERINIT.EXE >
[2010-06-21 13:58:22 | 000,024,416 | ---- | M] (Microsoft Corporation) MD5=09E2D2EC83F83B59691DE3CB283C9BBF -- C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2010-06-21 13:52:30 | 000,025,936 | ---- | M] (Microsoft Corporation) MD5=16A1750C90C84815D6B4ABC5B9454B26 -- C:\WINDOWS\LastGood\system32\userinit.exe
[2010-06-21 13:57:32 | 000,025,936 | ---- | M] (Microsoft Corporation) MD5=16A1750C90C84815D6B4ABC5B9454B26 -- C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2010-06-21 13:52:30 | 000,025,936 | ---- | M] (Microsoft Corporation) MD5=16A1750C90C84815D6B4ABC5B9454B26 -- C:\WINDOWS\system32\userinit.exe

< MD5 for: WSCNTFY.EXE >
[2010-07-11 17:27:12 | 000,013,536 | ---- | M] (Microsoft Corporation) MD5=1432AACDF69334B9305F0E163DF75A11 -- C:\WINDOWS\LastGood\system32\wscntfy.exe
[2010-07-11 17:27:12 | 000,013,536 | ---- | M] (Microsoft Corporation) MD5=1432AACDF69334B9305F0E163DF75A11 -- C:\WINDOWS\system32\wscntfy.exe
[2010-06-21 13:57:36 | 000,013,536 | ---- | M] (Microsoft Corporation) MD5=28345CC26F676AA1BD65E82562A3F23C -- C:\WINDOWS\ServicePackFiles\i386\wscntfy.exe
[2010-06-21 13:58:46 | 000,013,552 | ---- | M] (Microsoft Corporation) MD5=A03E215FF5CA42EA806BD48B39270929 -- C:\WINDOWS\$NtServicePackUninstall$\wscntfy.exe

< MD5 for: WUAUCLT.EXE >
[2010-06-21 13:57:28 | 000,110,872 | ---- | M] (Microsoft Corporation) MD5=16A492BFD3E5EFE041151E1D04E17D73 -- C:\WINDOWS\ServicePackFiles\i386\wuauclt.exe
[2010-06-21 13:58:46 | 000,110,888 | ---- | M] (Microsoft Corporation) MD5=5B5A45A52491E009715EE680B1770AB1 -- C:\WINDOWS\$NtServicePackUninstall$\wuauclt.exe
[2010-07-11 17:27:20 | 000,046,924 | ---- | M] (Microsoft Corporation) MD5=ECCCBFFC9B08306C57A535809A05E5CA -- C:\WINDOWS\LastGood\system32\wuauclt.exe
[2010-07-11 17:27:20 | 000,046,924 | ---- | M] (Microsoft Corporation) MD5=ECCCBFFC9B08306C57A535809A05E5CA -- C:\WINDOWS\system32\wuauclt.exe

< End of report >
  • 0

#15
cap10h

cap10h

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
regarding the ESET Online Scanner. I have error message says:
windows has found a problem with this file: onlinescanner.cab
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP